CVE-2020-36658: High severity lemonldap::ng apache vulnerability
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36658?
CVE-2020-36658 is classified as a moderate severity vulnerability.
How do I fix CVE-2020-36658?
To fix CVE-2020-36658, upgrade to libapache-session-ldap-perl version 0.5-1 or later.
Which versions of libapache-session-ldap-perl are affected by CVE-2020-36658?
Versions up to and including 0.4-1 of libapache-session-ldap-perl are affected by CVE-2020-36658.
Does CVE-2020-36658 involve SSL certificate validation?
Yes, CVE-2020-36658 involves a lack of default X.509 certificate validation when connecting to remote LDAP backends.
Is there a workaround for CVE-2020-36658?
A possible workaround for CVE-2020-36658 is to manually configure the SSL settings to enforce certificate validation.