Vulnerability Description
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lemonldap-Ng | Lemonldap\ | <= 2.0.11, \ |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8d3b763b6af2b8a9c4ad27PatchThird Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2539ExploitPatchThird Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/tagsPatchThird Party Advisory
- https://www.debian.org/security/2021/dsa-4943Third Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8d3b763b6af2b8a9c4ad27PatchThird Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2539ExploitPatchThird Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/tagsPatchThird Party Advisory
- https://www.debian.org/security/2021/dsa-4943Third Party Advisory
FAQ
What is CVE-2021-35472?
CVE-2021-35472 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker mi...
How severe is CVE-2021-35472?
CVE-2021-35472 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-35472?
Check the references section above for vendor advisories and patch information. Affected products include: Lemonldap-Ng Lemonldap\, Debian Debian Linux.