First published: Sun Jul 17 2022(Updated: )
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LemonLDAP::NG | <=2.0.8 | |
Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-16093 is high with a severity value of 7.5.
CVE-2020-16093 affects LemonLDAP::NG versions through 2.0.8 and Debian Debian Linux 10.0.
CVE-2020-16093 is a vulnerability in LemonLDAP::NG that allows for the possibility of not checking the validity of X.509 certificates when connecting to remote LDAP backends.
To fix the vulnerability in LemonLDAP::NG, update to version 2.0.9 or later.
To fix the vulnerability in Debian Debian Linux, update to the latest available version.