CVE-2020-16093: High severity lemonldap::ng vulnerability
Published Jul 17, 2022
·Updated
In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
Affected Software
2 affected components
lemonldap-ng Lemonldap\<=2.0.8
Debian Debian Linux=10.0
Remediation
Event History
Jul 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-16093?
The severity of CVE-2020-16093 is high with a severity value of 7.5.
2
How does CVE-2020-16093 affect LemonLDAP::NG and Debian Debian Linux?
CVE-2020-16093 affects LemonLDAP::NG versions through 2.0.8 and Debian Debian Linux 10.0.
3
What is the vulnerability description of CVE-2020-16093?
CVE-2020-16093 is a vulnerability in LemonLDAP::NG that allows for the possibility of not checking the validity of X.509 certificates when connecting to remote LDAP backends.
4
How can I fix the vulnerability in LemonLDAP::NG?
To fix the vulnerability in LemonLDAP::NG, update to version 2.0.9 or later.
5
How can I fix the vulnerability in Debian Debian Linux?
To fix the vulnerability in Debian Debian Linux, update to the latest available version.