An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lemonldap-ng
Lemonldap-ng lemonldap-ng |
|
Weaknesses | CWE-613 | |
CPEs | cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:* | |
Vendors & Products |
Lemonldap-ng
Lemonldap-ng lemonldap-ng |
|
Metrics |
cvssV3_1
|
Sun, 10 Nov 2024 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-10T00:00:00
Updated: 2024-11-19T19:34:45.685Z
Reserved: 2021-06-23T00:00:00
Link: CVE-2021-35473
Vulnrichment
Updated: 2024-11-19T19:29:31.821Z
NVD
Status : Awaiting Analysis
Published: 2024-11-10T23:15:04.383
Modified: 2024-11-19T20:35:13.347
Link: CVE-2021-35473
Redhat
No data.