DSA-4943-1 lemonldap-ng -- security update

Related Vulnerabilities: CVE-2021-35472  

Several vulnerabilities were discovered in lemonldap-ng, a Web-SSO system. The flaws could result in information disclosure, authentication bypass, or could allow an attacker to increase its authentication level or impersonate another user, especially when lemonldap-ng is configured to increase authentication level for users authenticated via a second factor. For the stable distribution (buster), these problems have been fixed in version 2.0.2+ds-7+deb10u6. We recommend that you upgrade your lemonldap-ng packages. For the detailed security status of lemonldap-ng please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lemonldap-ng

Debian Security Advisory

DSA-4943-1 lemonldap-ng -- security update

Date Reported:
23 Jul 2021
Affected Packages:
lemonldap-ng
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2021-35472.
More information:

Several vulnerabilities were discovered in lemonldap-ng, a Web-SSO system. The flaws could result in information disclosure, authentication bypass, or could allow an attacker to increase its authentication level or impersonate another user, especially when lemonldap-ng is configured to increase authentication level for users authenticated via a second factor.

For the stable distribution (buster), these problems have been fixed in version 2.0.2+ds-7+deb10u6.

We recommend that you upgrade your lemonldap-ng packages.

For the detailed security status of lemonldap-ng please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lemonldap-ng