CVE-2025-31510

NameCVE-2025-31510
DescriptionXSS/HTML Injection through tab parameter when using "Choice" authentication module
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4119-1, DSA-5897-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lemonldap-ng (PTS)bullseye2.0.11+ds-4+deb11u5vulnerable
bullseye (security)2.0.11+ds-4+deb11u7fixed
bookworm2.16.1+ds-deb12u5vulnerable
bookworm (security)2.16.1+ds-deb12u6fixed
sid, trixie2.21.0+ds-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lemonldap-ngsourcebullseye2.0.11+ds-4+deb11u7DLA-4119-1
lemonldap-ngsourcebookworm2.16.1+ds-deb12u6DSA-5897-1
lemonldap-ngsource(unstable)2.21.0+ds-1

Notes

https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3341
Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/a790b15e94f1435d9dfe1fe30750f35d54ed072a (v2.16.5)
Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/d27dbb12bd69e2551e819da898943a11ffd15673 (v2.21.0)
Introduced in: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/9620e6870a0102365cb0e5bc5d1f1cd17235bb5d (v2.0.8)

Search for package or bug name: Reporting problems