PT-2022-11318 · Unknown · Lemonldap::Ng

Maxbes

+1

·

Published

2022-07-17

·

Updated

2024-11-13

·

CVE-2021-40874

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LemonLDAP::NG version 2.0.13
Description An issue was discovered in LemonLDAP::NG when using the RESTServer plug-in for a REST password validation service and the Kerberos authentication method combined with another method using the Combination authentication plug-in. In this scenario, any password will be recognized as valid for an existing user.
Recommendations For LemonLDAP::NG version 2.0.13, consider disabling the Combination authentication plug-in or the Kerberos authentication method as a temporary workaround until a patch is available. Restrict access to the REST password validation service to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-40874

Affected Products

Lemonldap::Ng