PT-2013-1941 · Lemonldap+1 · Lemonldap::Ng+1

Frédéric Basse

·

Published

2013-01-01

·

Updated

2013-01-07

·

CVE-2012-6426

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LemonLDAP::NG versions prior to 1.2.3
Description The issue allows remote attackers to bypass intended access-control restrictions via crafted SAML data, due to the lack of signature-verification capability of the Lasso library.
Recommendations For versions prior to 1.2.3, update to version 1.2.3 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6426

Affected Products

Lasso
Lemonldap::Ng