CVE-2023-28862

NameCVE-2023-28862
DescriptionAn issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lemonldap-ng (PTS)buster2.0.2+ds-7+deb10u7vulnerable
buster (security)2.0.2+ds-7+deb10u8vulnerable
bullseye2.0.11+ds-4+deb11u4fixed
bookworm, sid2.16.1+ds-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lemonldap-ngsourcebullseye2.0.11+ds-4+deb11u4
lemonldap-ngsource(unstable)2.16.1+ds-1

Notes

[buster] - lemonldap-ng <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems