First published: Fri Jun 28 2019(Updated: )
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LemonLDAP::NG | <1.9.20 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13031 is classified as a medium severity vulnerability due to its potential for XML External Entity (XXE) attacks.
To fix CVE-2019-13031, upgrade to LemonLDAP::NG version 1.9.20 or later.
CVE-2019-13031 is an XML External Entity (XXE) vulnerability.
By default, the notification server is not enabled and has a "deny all" rule, reducing risk.
LemonLDAP::NG versions before 1.9.20 and Debian GNU/Linux version 8.0 are affected by CVE-2019-13031.