CVE-2022-37186

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*

History

26 Apr 2023, 16:30

Type Values Removed Values Added
References (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758 - (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758 - Exploit, Issue Tracking, Patch, Vendor Advisory
References (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4 - (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4 - Patch
References (CONFIRM) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15 - (CONFIRM) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15 - Patch, Release Notes
References (MISC) https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html - (MISC) https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html - Mailing List, Third Party Advisory
CWE CWE-613
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
First Time Lemonldap-ng lemonldap\
Lemonldap-ng
CPE cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*

16 Apr 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-16 02:15

Updated : 2023-12-10 15:01


NVD link : CVE-2022-37186

Mitre link : CVE-2022-37186

CVE.ORG link : CVE-2022-37186


JSON object : View

Products Affected

lemonldap-ng

  • lemonldap\
CWE
CWE-613

Insufficient Session Expiration