CVE-2019-15941
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- lemonldap-ng/lemonldap\ · debian/debian linux
- Source
- cve@mitre.org
References
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1881Third Party Advisory
- https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-6-is-out/Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/46Mailing List, Third Party Advisory
- https://www.debian.org/security/2019/dsa-4533Third Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1881Third Party Advisory
- https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-6-is-out/Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/46Mailing List, Third Party Advisory
- https://www.debian.org/security/2019/dsa-4533Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.