An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
History

Mon, 03 Nov 2025 23:30:00 +0000

Type Values Removed Values Added
References

Thu, 21 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Lemonldap-ng
Lemonldap-ng lemonldap-ng
Weaknesses CWE-276
CPEs cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:*
Vendors & Products Lemonldap-ng
Lemonldap-ng lemonldap-ng
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 06:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-18T00:00:00.000Z

Updated: 2025-11-03T22:28:41.701Z

Reserved: 2024-11-18T00:00:00.000Z

Link: CVE-2024-52946

cve-icon Vulnrichment

Updated: 2024-11-21T17:06:16.041Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-18T06:15:06.460

Modified: 2025-11-03T23:17:15.697

Link: CVE-2024-52946

cve-icon Redhat

No data.