CVE-2019-15941: Critical severity lemonldap::ng vulnerability
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15941?
The severity of CVE-2019-15941 is rated as critical with a CVSS score of 9.8.
How can an attacker bypass access control rules in LemonLDAP::NG 2.x through 2.0.5 via CVE-2019-15941?
An attacker can bypass access control rules by sending a crafted OpenID Connect authorization request to exploit the vulnerability.
What software versions are affected by CVE-2019-15941?
LemonLDAP::NG versions 2.0.0 to 2.0.5 are affected, along with specific Debian Linux versions.
Are there any known remediation versions for CVE-2019-15941?
Remediation versions include LemonLDAP::NG 2.0.2+ds-7+deb10u7, 2.0.2+ds-7+deb10u10, 2.0.11+ds-4+deb11u5, 2.16.1+ds-deb12u2, and 2.17.1+ds-1.
Where can I find more information about CVE-2019-15941?
For more information, you can refer to the provided references: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1881, https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-6-is-out/, and https://seclists.org/bugtraq/2019/Sep/46.