Security Advisories (1)
CVE-2021-40874 (2022-07-18)

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

Modules

The Apache protection module part of Lemonldap::NG Web-SSO system.
Apache client for Lemonldap::NG FastCGI server.
Base library for protected PSGI applications.
Base library for protected REST APIs of Lemonldap::NG.
Special handler for Lemonldap::NG Portal
authentication middleware for Lemonldap-NG

Provides

in lib/Lemonldap/NG/Handler/ApacheMP2.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/AuthBasic.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/CDA.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/DevOps.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/DevOpsST.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/Fail.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/Main.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/Menu.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/OAuth2.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/Request.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/SecureToken.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/ServiceToken.pm
in lib/Lemonldap/NG/Handler/ApacheMP2/ZimbraPreAuth.pm
in lib/Lemonldap/NG/Handler/Lib/AuthBasic.pm
in lib/Lemonldap/NG/Handler/Lib/CDA.pm
in lib/Lemonldap/NG/Handler/Lib/DevOps.pm
in lib/Lemonldap/NG/Handler/Lib/Fail.pm
in lib/Lemonldap/NG/Handler/Lib/OAuth2.pm
in lib/Lemonldap/NG/Handler/Lib/PSGI.pm
in lib/Lemonldap/NG/Handler/Lib/SecureToken.pm
in lib/Lemonldap/NG/Handler/Lib/ServiceToken.pm
in lib/Lemonldap/NG/Handler/Lib/Status.pm
in lib/Lemonldap/NG/Handler/Lib/StatusConstants.pm
in lib/Lemonldap/NG/Handler/Lib/ZimbraPreAuth.pm
in lib/Lemonldap/NG/Handler/Main.pm
in lib/Lemonldap/NG/Handler/Main/Init.pm
in lib/Lemonldap/NG/Handler/Main/Reload.pm
in lib/Lemonldap/NG/Handler/Main/Run.pm
in lib/Lemonldap/NG/Handler/Main/SharedVariables.pm
in lib/Lemonldap/NG/Handler/Main/Init.pm
in lib/Lemonldap/NG/Handler/Main/Jail.pm
in lib/Lemonldap/NG/Handler/Main/Reload.pm
in lib/Lemonldap/NG/Handler/Main/Run.pm
in lib/Lemonldap/NG/Handler/Main/SharedVariables.pm
in lib/Lemonldap/NG/Handler/PSGI/AuthBasic.pm
in lib/Lemonldap/NG/Handler/PSGI/CDA.pm
in lib/Lemonldap/NG/Handler/PSGI/Fail.pm
in lib/Lemonldap/NG/Handler/PSGI/Main.pm
in lib/Lemonldap/NG/Handler/PSGI/OAuth2.pm
in lib/Lemonldap/NG/Handler/PSGI/ServiceToken.pm
in lib/Lemonldap/NG/Handler/Server.pm
in lib/Lemonldap/NG/Handler/Server/AuthBasic.pm
in lib/Lemonldap/NG/Handler/Server/CDA.pm
in lib/Lemonldap/NG/Handler/Server/DevOps.pm
in lib/Lemonldap/NG/Handler/Server/DevOpsST.pm
in lib/Lemonldap/NG/Handler/Server/Fail.pm
in lib/Lemonldap/NG/Handler/Server/Main.pm
in lib/Lemonldap/NG/Handler/Server/Nginx.pm
in lib/Lemonldap/NG/Handler/Server/OAuth2.pm
in lib/Lemonldap/NG/Handler/Server/SecureToken.pm
in lib/Lemonldap/NG/Handler/Server/ServiceToken.pm
in lib/Lemonldap/NG/Handler/Server/ZimbraPreAuth.pm