Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2024-48933 A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the log… Lemonldap\ 2.19.3+ Fix from $1,6002024-10-09 CRITICAL 9.8 CVE-2019-19791 In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoin… Lemonldap\ 2.0.7+ Fix from $2,3002023-05-29 MEDIUM 5.9 CVE-2022-37186 In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can… Lemonldap\ 2.0.15+ Fix from $1,6002023-04-16 CRITICAL 9.8 CVE-2023-28862 An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a p… Lemonldap\ 2.16.1+ Fix from $2,3002023-03-31 HIGH 8.1 CVE-2020-36659 In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, bec… Apache\ 1.3.6+ Fix from $1,9502023-01-27 HIGH 8.1 CVE-2020-36658 In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the… Apache\ 0.5+ Fix from $1,9502023-01-27 HIGH 7.5 CVE-2012-6426 LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended … Lemonldap\ after 1.2.2 Fix from $1,9502013-01-01