VDB

CVE-2020-16093

CVE-2020-16093 PUBLISHED

In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

EPSS 0.45% · 64.0th percentile

Risk Scores

EPSS Score
0.45%
64.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlemonldap-ng0, 1.4.6-3, 1.4.6-1
Ubuntu:20.04:LTSlemonldap-ng2.0.5+ds-2, 0, 2.0.6+ds-2
Ubuntu:18.04:LTSlemonldap-ng1.9.13-2, 1.9.14-1, 1.9.16-2

Timeline

  • Jul 17, 2022 CVE Published
  • Jul 18, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 20, 2022 EPSS Score
  • Dec 6, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
  • Apr 26, 2023 EPSS Score
  • Jun 12, 2023 EPSS Score
  • Jul 29, 2023 EPSS Score
  • Sep 14, 2023 EPSS Score
  • Oct 31, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›