CVE-2019-1204622.05.2019, 16:29LemonLDAP::NG -2.0.3 has Incorrect Access Control.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTPrimary9.8 CRITICALNETWORKLOWNONECVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HBase ScoreCVSS 3.xEPSS ScorePercentile: UnknownAffected Products (NVD)VendorProductVersiondebiandebian_linux9.0𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenamelemonldap-ngbookworm2.16.1+ds-deb12u2fixedbullseye2.0.11+ds-4+deb11u5fixedsid2.20.0+ds-2fixedtrixie2.20.0+ds-2fixedUbuntu ReleasesUbuntu ProductCodenamelemonldap-ngbionicneeds-triagecosmicignoreddiscoignoredeoanignoredfocalneeds-triagegroovyignoredhirsuteignoredimpishignoredjammyneeds-triagekineticignoredlunarnot-affectedmanticnot-affectednoblenot-affectedtrustydnexenialneeds-triageKnown Exploits!https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742Common Weakness EnumerationCWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.Referenceshttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/commits/masterhttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1743https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1744https://lemonldap-ng.org/downloadhttps://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-1-9-19-is-out/https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-4-is-out/https://seclists.org/bugtraq/2019/May/38https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/commits/masterhttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1743https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1744https://lemonldap-ng.org/downloadhttps://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-1-9-19-is-out/https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-4-is-out/https://seclists.org/bugtraq/2019/May/38