An issue was discovered in LemonLDAP::NG before 2.16.1....
Critical severity
Unreviewed
Published
Mar 31, 2023
to the GitHub Advisory Database
•
Updated Jul 14, 2023
Description
Published by the National Vulnerability Database
Mar 31, 2023
Published to the GitHub Advisory Database
Mar 31, 2023
Last updated
Jul 14, 2023
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny session creation after the store step does not deny an AuthBasic session.
References