CVE-2019-13031: XEE
Published Jun 28, 2019
·Updated
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.
Affected Software
2 affected components
lemonldap-ng Lemonldap\<1.9.20
Debian Debian Linux=8.0
Event History
Jun 28, 2019
CVE Published
via MITRE·10:42 PM
Data Sourced
via MITRE·10:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13031?
CVE-2019-13031 is classified as a medium severity vulnerability due to its potential for XML External Entity (XXE) attacks.
2
How do I fix CVE-2019-13031?
To fix CVE-2019-13031, upgrade to LemonLDAP::NG version 1.9.20 or later.
3
What type of vulnerability is CVE-2019-13031?
CVE-2019-13031 is an XML External Entity (XXE) vulnerability.
4
Is the notification server enabled by default in CVE-2019-13031?
By default, the notification server is not enabled and has a "deny all" rule, reducing risk.
5
Which software versions are affected by CVE-2019-13031?
LemonLDAP::NG versions before 1.9.20 and Debian GNU/Linux version 8.0 are affected by CVE-2019-13031.