Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2020-24660

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Attacker Value
Unknown

CVE-2019-15941

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
Attacker Value
Unknown

CVE-2019-13031

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
0
Attacker Value
Unknown

CVE-2019-12046

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
0
Attacker Value
Unknown

CVE-2012-6426

Disclosure Date: January 01, 2013 (last updated October 05, 2023)
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
0