Back to search
CVE-2021-35472
Published: Jul 27, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2539
x_refsource_MISC
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/tags
x_refsource_MISC
DSA-4943
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now