Debian Security Advisory
DSA-4943-1 lemonldap-ng -- security update
- Date Reported:
- 23 Jul 2021
- Affected Packages:
- lemonldap-ng
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2021-35472.
- More information:
-
Several vulnerabilities were discovered in lemonldap-ng, a Web-SSO system. The flaws could result in information disclosure, authentication bypass, or could allow an attacker to increase its authentication level or impersonate another user, especially when lemonldap-ng is configured to increase authentication level for users authenticated via a second factor.
For the stable distribution (buster), these problems have been fixed in version 2.0.2+ds-7+deb10u6.
We recommend that you upgrade your lemonldap-ng packages.
For the detailed security status of lemonldap-ng please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lemonldap-ng