Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 10 Buster DLA-3496-1 Moderate: Lemonldap-ng Impersonation Risk Fixed

debian lts
Calendar Grey July 14, 2023
Dist Debian Esm H88
Debian LTS enhances security in Lemonldap::NG to combat user impersonation risks linked to vulnerable 2FA procedures. Discover the details of this update!
Issues were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to impersonation of users with a second factor authentication

Summary

Weak session ID generation in the AuthBasic handler and incorrect
failure handling during a password check allow attackers to bypass 2FA
verification. Any plugin that tries to deny session creation after the
store step does not deny an AuthBasic session.

Using the AuthBasic handler is now refused for users with a second
factor. Admins who are *absolutely sure* that such accounts should be
able to use AuthBasic handlers (which are password only) can append `and
not $ENV{AuthBasic}` to the 2FA activation rules.

For Debian 10 buster, these problems have been fixed in version
2.0.2+ds-7+deb10u9.

We recommend that you upgrade your lemonldap-ng packages.

For the detailed security status of lemonldap-ng please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/lemonldap-ng

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: lemonldap-ng
Version: 2.0.2+ds-7+deb10u9
CVE ID: CVE-2023-28862

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here