| Vulnerability Name: | CVE-2019-12046 (CCN-161186) | ||||||||||||||||||||
| Assigned: | 2019-05-13 | ||||||||||||||||||||
| Published: | 2019-05-13 | ||||||||||||||||||||
| Updated: | 2020-08-24 | ||||||||||||||||||||
| Summary: | LemonLDAP::NG -2.0.3 has Incorrect Access Control. | ||||||||||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-522 | ||||||||||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-12046 Source: CCN Type: Debian Bug report logs - #928944 CVE-2019-12046: lemonldap-ng tokens allows anonymous session when stored in session DB Source: XF Type: UNKNOWN lemonldapng-cve201912046-sec-bypass(161186) Source: MISC Type: Third Party Advisory https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/commits/master Source: MISC Type: Exploit, Third Party Advisory https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742 Source: MISC Type: Third Party Advisory https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1743 Source: MISC Type: Third Party Advisory https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1744 Source: MISC Type: Product, Vendor Advisory https://lemonldap-ng.org/download Source: CONFIRM Type: Release Notes, Third Party Advisory https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-1-9-19-is-out/ Source: CONFIRM Type: Release Notes, Third Party Advisory https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-4-is-out/ Source: CCN Type: BugTraq Mailing List, Tue, 14 May 2019 21:20:29 +0000 [SECURITY] [DSA 4446-1] lemonldap-ng security update Source: MISC Type: Mailing List, Third Party Advisory https://seclists.org/bugtraq/2019/May/38 Source: CCN Type: lemonldap-ng Web site OpenID-Connect, CAS and SAML compatible Web-SSO system | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||