CVE-2024-52946

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-18 06:15

Updated : 2024-11-21 18:15


NVD link : CVE-2024-52946

Mitre link : CVE-2024-52946

CVE.ORG link : CVE-2024-52946


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions