CVE-2019-1204622.05.2019, 16:29LemonLDAP::NG -2.0.3 has Incorrect Access Control.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST9.8 CRITICALNETWORKLOWNONECVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 81%VendorProductVersiondebiandebian_linux9.0𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenamelemonldap-ngbullseye2.0.11+ds-4+deb11u5fixedbookworm2.16.1+ds-deb12u2fixedsid2.20.0+ds-2fixedtrixie2.20.0+ds-2fixedUbuntu ReleasesUbuntu ProductCodenamelemonldap-ngnoblenot-affectedmanticnot-affectedlunarnot-affectedkineticignoredjammyneeds-triageimpishignoredhirsuteignoredgroovyignoredfocalneeds-triageeoanignoreddiscoignoredcosmicignoredbionicneeds-triagexenialneeds-triagetrustydneKnown Exploits!https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742Common Weakness EnumerationCWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.Referenceshttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/commits/masterhttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1743https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1744https://lemonldap-ng.org/downloadhttps://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-1-9-19-is-out/https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-4-is-out/https://seclists.org/bugtraq/2019/May/38https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/commits/masterhttps://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1743https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1744https://lemonldap-ng.org/downloadhttps://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-1-9-19-is-out/https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-4-is-out/https://seclists.org/bugtraq/2019/May/38