CVE-2024-52946

NameCVE-2024-52946
DescriptionAn issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lemonldap-ng (PTS)jessie, jessie (lts)1.3.3-1+deb8u2vulnerable
stretch (security), stretch (lts), stretch1.9.7-3+deb9u4vulnerable
buster (security), buster, buster (lts)2.0.2+ds-7+deb10u10vulnerable
bullseye2.0.11+ds-4+deb11u5vulnerable
bookworm2.16.1+ds-deb12u3vulnerable
sid, trixie2.20.1+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lemonldap-ngsourcejessie(unfixed)end-of-life
lemonldap-ngsourcestretch(unfixed)end-of-life
lemonldap-ngsource(unstable)2.20.1+ds-1

Notes

https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3255

Search for package or bug name: Reporting problems