CVE-2021-35472: High severity lemonldap::ng vulnerability
Published Jul 27, 2021
·Updated
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.
Affected Software
3 affected componentsFixes available
debian/lemonldap-ng
2.0.2+ds-7+deb10u72.0.2+ds-7+deb10u102.0.11+ds-4+deb11u52.16.1+ds-deb12u22.17.1+ds-1
lemonldap-ng Lemonldap\<=2.0.11
Debian Debian Linux=10.0
Remediation
Patch Available
Event History
Jul 27, 2021
CVE Published
via MITRE·05:32 AM
Data Sourced
via MITRE·05:32 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-35472?
The severity of CVE-2021-35472 is rated as high with a CVSS score of 8.8.
2
How can an attacker exploit CVE-2021-35472 vulnerability?
An attacker can exploit CVE-2021-35472 by causing session cache corruption, leading to authorization bypass or spoofing by making many authentication attempts.
3
What is the affected software for CVE-2021-35472?
The affected software for CVE-2021-35472 includes LemonLDAP::NG versions before 2.0.12 and specific Debian packages as listed in the advisory.