CVE-2021-35472
30.07.2021, 14:15
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.Enginsight
Vendor | Product | Version |
---|---|---|
lemonldap-ng | lemonldap\ | 𝑥 ≤ 2.0.11 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References