Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lemonldap\ MEDIUM 6.1
CVE-2024-48933

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the log…

Fix: 2.19.3+
Fix from $1,600 2024-10-09
Lemonldap\ CRITICAL 9.8
CVE-2019-19791

In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoin…

Fix: 2.0.7+
Fix from $2,300 2023-05-29
Lemonldap\ MEDIUM 5.9
CVE-2022-37186

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can…

Fix: 2.0.15+
Fix from $1,600 2023-04-16
Lemonldap\ CRITICAL 9.8
CVE-2023-28862

An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a p…

Fix: 2.16.1+
Fix from $2,300 2023-03-31
Apache\ HIGH 8.1
CVE-2020-36659

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, bec…

Fix: 1.3.6+
Fix from $1,950 2023-01-27
Apache\ HIGH 8.1
CVE-2020-36658

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the…

Fix: 0.5+
Fix from $1,950 2023-01-27
Lemonldap\ HIGH 7.5
CVE-2012-6426

LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended …

Fix: after 1.2.2
Fix from $1,950 2013-01-01