Search Results (Refine Search)
- Keyword (text search): cpe:2.3:a:lemonldap-ng:lemonldap\:\::1.0:rc1:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2019-13031 |
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule. Published: June 28, 2019; 7:15:09 PM -0400 |
V4.0:(not available) V3.0: 8.1 HIGH V2.0: 6.8 MEDIUM |
CVE-2012-6426 |
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data. Published: January 01, 2013; 10:55:02 AM -0500 |
V4.0:(not available) V3.x:(not available) V2.0: 7.5 HIGH |