Security Advisories (2)
CVE-2021-35472 (2021-07-30)

An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.

CVE-2021-35473

OAuth2 handler does not verify access token validity

Modules

Perl extension for managing Lemonldap::NG Web-SSO system.
Static files generator of Lemonldap::NG Web-SSO system.
EXPERIMENTAL command line manager for Lemonldap::NG web SSO system.
Configuration management part of Lemonldap::NG::Manager.
Perl extension for parsing new uploaded configurations.
Notifications explorer component of Lemonldap::NG::Manager.
Sessions explorer component of Lemonldap::NG::Manager.

Provides

in lib/Lemonldap/NG/Manager/Attributes.pm
in lib/Lemonldap/NG/Manager/Build/Attributes.pm
in lib/Lemonldap/NG/Manager/Build/CTrees.pm
in lib/Lemonldap/NG/Manager/Build/Tree.pm
in lib/Lemonldap/NG/Manager/Cli/Lib.pm
in lib/Lemonldap/NG/Manager/Cli.pm
in lib/Lemonldap/NG/Manager/Conf/Tests.pm
in lib/Lemonldap/NG/Manager/Conf/Zero.pm
in lib/Lemonldap/NG/Manager/Constants.pm
in lib/Lemonldap/NG/Manager/Lib.pm