LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-01-01 07:55
Updated : 2013-01-06 21:00
NVD link : CVE-2012-6426
Mitre link : CVE-2012-6426
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
lemonldap-ng
- lemonldap\