Vulnerability Description
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lemonldap-Ng | Lemonldap\ | < 1.9.20, \ |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1820Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00003.htmlThird Party Advisory
- https://www.calypt.com/blog/index.php/cve-2019-13031-xxe-on-lemonldapng-2-0-5/
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1820Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00003.htmlThird Party Advisory
- https://www.calypt.com/blog/index.php/cve-2019-13031-xxe-on-lemonldapng-2-0-5/
FAQ
What is CVE-2019-13031?
CVE-2019-13031 is a vulnerability with a CVSS score of 8.1 (HIGH). LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" ru...
How severe is CVE-2019-13031?
CVE-2019-13031 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13031?
Check the references section above for vendor advisories and patch information. Affected products include: Lemonldap-Ng Lemonldap\, Debian Debian Linux.