CVE-2020-36659: High severity lemonldap::ng apache vulnerability
Published Jan 27, 2023
·Updated
In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
Affected Software
2 affected components
lemonldap-ng Apache\<1.3.6
Debian Debian Linux=10.0
Remediation
Event History
Jan 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-36659?
The severity of CVE-2020-36659 is rated as high with a CVSS score of 8.1.
2
How can I fix CVE-2020-36659?
To fix CVE-2020-36659, it is recommended to update to Apache::Session::Browseable version 1.3.6 or later and ensure the X.509 certificate validity is checked when connecting to remote LDAP backends.