Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-40874

Опубликовано: 18 июл. 2022
Источник: debian
EPSS Низкий

Описание

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lemonldap-ngfixed2.0.14~exp+ds-1experimentalpackage
lemonldap-ngfixed2.0.14+ds-1package
lemonldap-ngfixed2.0.11+ds-4+deb11u1bullseyepackage
lemonldap-ngfixed2.0.2+ds-7+deb10u7busterpackage
lemonldap-ngnot-affectedstretchpackage

Примечания

  • https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2612

  • https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/66946e8f754812b375768c2124937137c856fe0c

EPSS

Процентиль: 53%
0.00307
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

CVSS3: 9.8
nvd
больше 3 лет назад

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

EPSS

Процентиль: 53%
0.00307
Низкий