VDB
CVE-2019-15941
CVE-2019-15941
PUBLISHED
CVSS 9.800000190734863 CRITICAL
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
EPSS 2.20% · 81.1th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.20%
81.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | lemonldap-ng | 0, 1.9.10-1, 1.9.14-1 |
| Ubuntu:16.04:LTS | lemonldap-ng | 0, 1.4.6-1, 1.4.6-3 |
Timeline
- Sep 25, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-15941 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-15941 third-party-advisory