An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 21 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lemonldap-ng
Lemonldap-ng lemonldap-ng |
|
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lemonldap-ng
Lemonldap-ng lemonldap-ng |
|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-18T00:00:00.000Z
Updated: 2025-11-03T22:28:41.701Z
Reserved: 2024-11-18T00:00:00.000Z
Link: CVE-2024-52946
Updated: 2024-11-21T17:06:16.041Z
Status : Awaiting Analysis
Published: 2024-11-18T06:15:06.460
Modified: 2025-11-03T23:17:15.697
Link: CVE-2024-52946
No data.