CVE-2012-6426: High severity lemonldap-ng Lemonldap\ vulnerability
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6426?
CVE-2012-6426 is classified with high severity due to its ability to allow remote attackers to bypass access-control restrictions.
How do I fix CVE-2012-6426?
The fix for CVE-2012-6426 is to upgrade LemonLDAP::NG to version 1.2.3 or later to ensure the use of signature verification in the Lasso library.
What impact does CVE-2012-6426 have on my system?
CVE-2012-6426 can potentially allow unauthorized access to sensitive areas of your application by manipulating SAML data.
Which versions of LemonLDAP::NG are affected by CVE-2012-6426?
All versions of LemonLDAP::NG prior to 1.2.3, including versions 1.2.2 and earlier, are affected by CVE-2012-6426.
Is my data at risk due to CVE-2012-6426?
Yes, if you are using an affected version of LemonLDAP::NG, your data may be at risk of unauthorized access.