CVE-2023-28862: Critical severity lemonldap::ng vulnerability
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28862?
CVE-2023-28862 has a high severity rating due to the ability to bypass two-factor authentication.
How do I fix CVE-2023-28862?
You can fix CVE-2023-28862 by upgrading to LemonLDAP::NG version 2.16.1 or later.
What kind of attack does CVE-2023-28862 allow?
CVE-2023-28862 allows attackers to bypass two-factor authentication through weak session ID generation.
Which versions of LemonLDAP::NG are affected by CVE-2023-28862?
CVE-2023-28862 affects all versions of LemonLDAP::NG prior to 2.16.1.
Is there a workaround for CVE-2023-28862?
Currently, the recommended action is to upgrade to the secure version, as no effective workaround is mentioned for CVE-2023-28862.