Security Advisories (2)
CVE-2020-16093 (2022-07-18)

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

CVE-2020-24660 (2020-09-14)

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

NAME

Lemonldap::NG::Handler::SympaAutoLogin - Perl extension to generate Sympa cookie for users authenticated by LemonLDAP::NG

SYNOPSIS

package My::Sympa;
use Lemonldap::NG::Handler::SympaAutoLogin;
@ISA = qw(Lemonldap::NG::Handler::SympaAutoLogin);

__PACKAGE__->init ( {

  # Sympa parameters
  sympaSecret => 'XXXX',
  sympaMailKey => 'mail',

  # See Lemonldap::NG::Handler for more
} );
1;

DESCRIPTION

Lemonldap::NG::Handler::SympaAutoLogin is a special Lemonldap::NG handler that generates Sympa cookie for authenticated users. Use it instead of classic Lemonldap::NG::Handler to protect your Sympa web server. You have to set the configuration key containing user email (parameter sympaMailKey) and to store Sympa secret (cookie parameter on Sympa configuration file) in the corresponding configuration parameter (sympaSecret)

Edit you Sympa vhost configuration like this:

<VirtualHost *> ServerName sympa.example.com

# Load Sympa Handler
PerlRequire __HANDLERDIR__/MyHandlerSympa.pm
PerlHeaderParserHandler My::Sympa

</VirtualHost>

EXPORT

See Lemonldap::NG::Handler

SEE ALSO

Lemonldap::NG::Handler

AUTHOR

Clement Oudot, <clem.oudot@gmail.com>
Xavier Guimard, <x.guimard@free.fr>

BUG REPORT

Use OW2 system to report bug or ask for features: http://jira.ow2.org

DOWNLOAD

Lemonldap::NG is available at http://forge.objectweb.org/project/showfiles.php?group_id=274

COPYRIGHT AND LICENSE

This library is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program. If not, see http://www.gnu.org/licenses/.