Security Advisories (2)
CVE-2020-16093 (2022-07-18)

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

CVE-2020-24660 (2020-09-14)

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

NAME

Lemonldap::NG::Portal::_CAS - Common CAS functions

SYNOPSIS

use Lemonldap::NG::Portal::_CAS;

DESCRIPTION

This module contains common methods for CAS

METHODS

getCasSession

Try to recover the CAS session corresponding to id and return session datas If id is set to undef, return a new session

returnCasValidateError

Return an error for CAS VALIDATE request

returnCasValidateSuccess

Return success for CAS VALIDATE request

deleteCasSecondarySessions

Find and delete CAS sessions bounded to a primary session

returnCasServiceValidateError

Return an error for CAS SERVICE VALIDATE request

returnCasServiceValidateSuccess

Return success for CAS SERVICE VALIDATE request

returnCasProxyError

Return an error for CAS PROXY request

returnCasProxySuccess

Return success for CAS PROXY request

deleteCasSession

Delete an opened CAS session

callPgtUrl

Call proxy granting URL on CAS client

SEE ALSO

Lemonldap::NG::Portal::IssuerDBCAS

AUTHOR

Clement Oudot, <coudot@linagora.com>

COPYRIGHT AND LICENSE

Copyright (C) 2010 by Clement Oudot

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself, either Perl version 5.10.0 or, at your option, any later version of Perl 5 you may have available.