Security Advisories (2)
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
- https://www.debian.org/security/2020/dsa-4762
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/releases/tag/0.5.2
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/security/advisories/GHSA-x44x-r84w-8v67
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/blob/master/changelog
No POD found for Metadata.pm.
Time to read the source?
Module Install Instructions
To install Lemonldap::NG::Common, copy and paste the appropriate command in to your terminal.
cpanm Lemonldap::NG::Common
perl -MCPAN -e shell
install Lemonldap::NG::Common
For more information on module installation, please visit the detailed CPAN module installation guide.