[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-15941 -- lemonldap-ng

ID: oval:org.secpod.oval:def:2004803Date: (C)2020-10-22   (M)2021-09-11
Class: VULNERABILITYFamily: unix




OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.

Platform:
Debian 10.x
Debian 9.x
Product:
lemonldap-ng
Reference:
CVE-2019-15941
CVE    1
CVE-2019-15941
CPE    3
cpe:/o:debian:debian_linux:10.x
cpe:/a:lemonldap-ng:lemonldap-ng
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies