LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
{
"binaries": [
{
"binary_version": "1.2.5-1",
"binary_name": "lemonldap-ng"
},
{
"binary_version": "1.2.5-1",
"binary_name": "lemonldap-ng-doc"
},
{
"binary_version": "1.2.5-1",
"binary_name": "liblemonldap-ng-conf-perl"
},
{
"binary_version": "1.2.5-1",
"binary_name": "liblemonldap-ng-handler-perl"
},
{
"binary_version": "1.2.5-1",
"binary_name": "liblemonldap-ng-manager-perl"
},
{
"binary_version": "1.2.5-1",
"binary_name": "liblemonldap-ng-portal-perl"
}
],
"availability": "No subscription required"
}