Security Advisories (2)
CVE-2020-16093 (2022-07-18)

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

CVE-2020-24660 (2020-09-14)

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

NAME

Lemonldap::NG::Portal::_CAS - Common CAS functions

SYNOPSIS

use Lemonldap::NG::Portal::_CAS;

DESCRIPTION

This module contains common methods for CAS

METHODS

getCasSession

Try to recover the CAS session corresponding to id and return session datas If id is set to undef, return a new session

returnCasValidateError

Return an error for CAS VALIDATE request

returnCasValidateSuccess

Return success for CAS VALIDATE request

deleteCasSecondarySessions

Find and delete CAS sessions bounded to a primary session

returnCasServiceValidateError

Return an error for CAS SERVICE VALIDATE request

returnCasServiceValidateSuccess

Return success for CAS SERVICE VALIDATE request

returnCasProxyError

Return an error for CAS PROXY request

returnCasProxySuccess

Return success for CAS PROXY request

deleteCasSession

Delete an opened CAS session

callPgtUrl

Call proxy granting URL on CAS client

SEE ALSO

Lemonldap::NG::Portal::IssuerDBCAS

AUTHOR

Clement Oudot, <clem.oudot@gmail.com>

BUG REPORT

Use OW2 system to report bug or ask for features: http://jira.ow2.org

DOWNLOAD

Lemonldap::NG is available at http://forge.objectweb.org/project/showfiles.php?group_id=274

COPYRIGHT AND LICENSE

This library is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program. If not, see http://www.gnu.org/licenses/.