CVE-2024-45160
EUVD-2024-4134009.10.2024, 05:15
Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lemonldap-ng | lemonldap-ng | 2.18.0 ≤ 𝑥 < 2.19.2 | ADP |
Debian Releases
Ubuntu Releases
References