LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "lemonldap-ng",
"binary_version": "1.2.5-1"
},
{
"binary_name": "lemonldap-ng-doc",
"binary_version": "1.2.5-1"
},
{
"binary_name": "liblemonldap-ng-conf-perl",
"binary_version": "1.2.5-1"
},
{
"binary_name": "liblemonldap-ng-handler-perl",
"binary_version": "1.2.5-1"
},
{
"binary_name": "liblemonldap-ng-manager-perl",
"binary_version": "1.2.5-1"
},
{
"binary_name": "liblemonldap-ng-portal-perl",
"binary_version": "1.2.5-1"
}
]
}