lemonldap-ng CVE Vulnerabilities & Metrics

Focus on lemonldap-ng vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About lemonldap-ng Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with lemonldap-ng. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total lemonldap-ng CVEs: 14
Earliest CVE date: 01 Jan 2013, 15:55 UTC
Latest CVE date: 09 Oct 2024, 23:15 UTC

Latest CVE reference: CVE-2024-48933

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -75.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -75.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical lemonldap-ng CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.85

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 2
7.0-8.9 4
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS lemonldap-ng CVEs

These are the five CVEs with the highest CVSS scores for lemonldap-ng, sorted by severity first and recency.

All CVEs for lemonldap-ng

CVE-2024-48933 lemonldap-ng vulnerability CVSS: 0 09 Oct 2024, 23:15 UTC

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.

CVE-2023-44469 lemonldap-ng vulnerability CVSS: 0 29 Sep 2023, 07:15 UTC

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

CVE-2019-19791 lemonldap-ng vulnerability CVSS: 0 29 May 2023, 19:15 UTC

In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.

CVE-2022-37186 lemonldap-ng vulnerability CVSS: 0 16 Apr 2023, 02:15 UTC

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.

CVE-2023-28862 lemonldap-ng vulnerability CVSS: 0 31 Mar 2023, 17:15 UTC

An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.

CVE-2020-36659 lemonldap-ng vulnerability CVSS: 0 27 Jan 2023, 05:15 UTC

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

CVE-2020-36658 lemonldap-ng vulnerability CVSS: 0 27 Jan 2023, 05:15 UTC

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

CVE-2021-40874 lemonldap-ng vulnerability CVSS: 0 18 Jul 2022, 00:15 UTC

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with the Combination authentication plug-in, any password will be recognized as valid for an existing user.

CVE-2020-16093 lemonldap-ng vulnerability CVSS: 0 18 Jul 2022, 00:15 UTC

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

CVE-2021-35472 lemonldap-ng vulnerability CVSS: 6.0 30 Jul 2021, 14:15 UTC

An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spoofing. By running a loop that makes many authentication attempts, an attacker might alternately be authenticated as one of two different users.

CVE-2020-24660 lemonldap-ng vulnerability CVSS: 7.5 14 Sep 2020, 13:15 UTC

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

CVE-2019-15941 lemonldap-ng vulnerability CVSS: 7.5 25 Sep 2019, 20:15 UTC

OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.

CVE-2019-13031 lemonldap-ng vulnerability CVSS: 6.8 28 Jun 2019, 23:15 UTC

LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.

CVE-2019-12046 lemonldap-ng vulnerability CVSS: 7.5 22 May 2019, 16:29 UTC

LemonLDAP::NG -2.0.3 has Incorrect Access Control.

CVE-2012-6426 lemonldap-ng vulnerability CVSS: 7.5 01 Jan 2013, 15:55 UTC

LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.