Security Advisories (2)
CVE-2021-35472 (2021-07-30)

An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.

CVE-2021-35473

OAuth2 handler does not verify access token validity

Modules

Common files for Lemonldap::NG infrastructure
Perl extension written to access to Lemonldap::NG Web-SSO sessions via SOAP.
Simple module to extend CGI to manage HTTP "If-Modified-Since / 304 Not Modified" system.
Extends SOAP::Lite to be compatible with CGI.
Wrapper for all SOAP functions of Lemonldap::NG CGIs.
Perl extension written to manage Lemonldap::NG Web-SSO configuration.
Perl extension written to access to Lemonldap::NG Web-SSO configuration via SOAP.
Provides notification messages system. UNAUTHORIZED
Contains functions that are automatically imported in Lemonldap::NG Safe objects to be used in expressions like rules, macros,...

Provides

in lib/Lemonldap/NG/Common/Apache/Session.pm
in lib/Lemonldap/NG/Common/Conf/CDBI.pm
in lib/Lemonldap/NG/Common/Conf/Constants.pm
in lib/Lemonldap/NG/Common/Conf/DBI.pm
in lib/Lemonldap/NG/Common/Conf/File.pm
in lib/Lemonldap/NG/Common/Conf/JSONFile.pm UNAUTHORIZED
in lib/Lemonldap/NG/Common/Conf/LDAP.pm
in lib/Lemonldap/NG/Common/Conf/RDBI.pm
in lib/Lemonldap/NG/Common/Conf/SAML/Metadata.pm
in lib/Lemonldap/NG/Common/Conf/Serializer.pm
in lib/Lemonldap/NG/Common/Conf/_DBI.pm
in lib/Lemonldap/NG/Common/Crypto.pm
in lib/Lemonldap/NG/Common/Notification/DBI.pm UNAUTHORIZED
in lib/Lemonldap/NG/Common/Notification/File.pm UNAUTHORIZED
in lib/Lemonldap/NG/Common/Notification/LDAP.pm UNAUTHORIZED
in lib/Lemonldap/NG/Common/Regexp.pm
in lib/Lemonldap/NG/Common/Safe.pm