An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
History

Thu, 21 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Lemonldap-ng
Lemonldap-ng lemonldap-ng
Weaknesses CWE-276
CPEs cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:*
Vendors & Products Lemonldap-ng
Lemonldap-ng lemonldap-ng
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 06:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-18T00:00:00

Updated: 2024-11-21T17:06:21.816Z

Reserved: 2024-11-18T00:00:00

Link: CVE-2024-52946

cve-icon Vulnrichment

Updated: 2024-11-21T17:06:16.041Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-18T06:15:06.460

Modified: 2024-11-21T18:15:13.120

Link: CVE-2024-52946

cve-icon Redhat

No data.