UBUNTU-CVE-2021-40874
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-40874
Summary:
Details: An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.
References: https://ubuntu.com/security/CVE-2021-40874, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2612, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/66946e8f754812b375768c2124937137c856fe0c, https://www.cve.org/CVERecord?id=CVE-2021-40874
Affected packages
Package
Name: lemonldap-ng
Purl: pkg:deb/ubuntu/lemonldap-ng?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
