CVE-2024-52946

NameCVE-2024-52946
DescriptionAn issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3979-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lemonldap-ng (PTS)bullseye2.0.11+ds-4+deb11u5vulnerable
bullseye (security)2.0.11+ds-4+deb11u7fixed
bookworm2.16.1+ds-deb12u5fixed
bookworm (security)2.16.1+ds-deb12u6fixed
trixie, sid2.21.0+ds-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lemonldap-ngsourcebullseye2.0.11+ds-4+deb11u6DLA-3979-1
lemonldap-ngsourcebookworm2.16.1+ds-deb12u4
lemonldap-ngsource(unstable)2.20.1+ds-1

Notes

https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3255
Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/63a045e4a4ad579559cfe04e644b0cefe2f1137b (v2.20.1)
Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/065b71ba4e97d7f8dbfe61900e9d4d587109f11b (v2.20.1)

Search for package or bug name: Reporting problems