CVE-2024-52946

NameCVE-2024-52946
DescriptionAn issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3979-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lemonldap-ng (PTS)bullseye2.0.11+ds-4+deb11u5vulnerable
bullseye (security)2.0.11+ds-4+deb11u6fixed
bookworm2.16.1+ds-deb12u3vulnerable
sid, trixie2.20.1+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lemonldap-ngsourcebullseye2.0.11+ds-4+deb11u6DLA-3979-1
lemonldap-ngsource(unstable)2.20.1+ds-1

Notes

[bookworm] - lemonldap-ng <no-dsa> (Minor issue, will be fixed via spu)
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3255
Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/63a045e4a4ad579559cfe04e644b0cefe2f1137b (v2.20.1)
Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/065b71ba4e97d7f8dbfe61900e9d4d587109f11b (v2.20.1)

Search for package or bug name: Reporting problems