Description
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3979-1 | lemonldap-ng security update |
References
History
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 21 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lemonldap-ng
Lemonldap-ng lemonldap-ng |
|
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lemonldap-ng
Lemonldap-ng lemonldap-ng |
|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T22:28:41.701Z
Reserved: 2024-11-18T00:00:00.000Z
Link: CVE-2024-52946
Updated: 2024-11-21T17:06:16.041Z
Status : Deferred
Published: 2024-11-18T06:15:06.460
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52946
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA