CVE-2021-40874: Critical severity lemonldap::ng vulnerability
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40874?
CVE-2021-40874 has been rated as a high severity vulnerability due to its potential to allow unauthorized access when exploiting improper authentication methods.
How do I fix CVE-2021-40874?
To fix CVE-2021-40874, you should upgrade to LemonLDAP::NG version 2.0.14 or later, which includes a patch for this vulnerability.
What software versions are affected by CVE-2021-40874?
CVE-2021-40874 affects LemonLDAP::NG version 2.0.13 specifically, as well as Debian GNU/Linux 10.0 if using the vulnerable plugin.
What authentication methods are involved in CVE-2021-40874?
CVE-2021-40874 involves the Kerberos authentication method in combination with other methods within the RESTServer plug-in.
Can CVE-2021-40874 be exploited remotely?
Yes, CVE-2021-40874 can potentially be exploited remotely, allowing attackers to bypass authentication under certain conditions.