CVE-2024-52946: High severity LemonLDAP NG vulnerability
An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52946?
CVE-2024-52946 has not been assigned a CVSS score, but it poses a significant security risk due to improper session handling.
How do I fix CVE-2024-52946?
To fix CVE-2024-52946, upgrade LemonLDAP::NG to version 2.20.1 or later to ensure proper session management.
Who is affected by CVE-2024-52946?
CVE-2024-52946 affects users of LemonLDAP::NG versions prior to 2.20.1 that have configured adaptive authentication rules.
What is the impact of CVE-2024-52946?
The impact of CVE-2024-52946 allows an authenticated user to improperly increase their authentication level.
Is there a workaround for CVE-2024-52946?
Currently, no official workaround is available for CVE-2024-52946, and users are advised to update to the patched version.