Vulnerability Database
Blog
FAQ
Docs
CVE-2019-12046
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-12046
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-12046.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-12046
Related
DLA-1790-1
DSA-4446-1
UBUNTU-CVE-2019-12046
Published
2019-05-22T16:29:01Z
Modified
2024-11-05T06:50:05.404428Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
References
https://lemonldap-ng.org/download
https://seclists.org/bugtraq/2019/May/38
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1742
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/commits/master
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1743
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1744
https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-1-9-19-is-out/
https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-4-is-out/
https://security-tracker.debian.org/tracker/CVE-2019-12046
Affected packages
Debian:11
/
lemonldap-ng
Package
Name
lemonldap-ng
Purl
pkg:deb/debian/lemonldap-ng?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.0.2+ds-7+deb10u1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:12
/
lemonldap-ng
Package
Name
lemonldap-ng
Purl
pkg:deb/debian/lemonldap-ng?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.0.2+ds-7+deb10u1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:13
/
lemonldap-ng
Package
Name
lemonldap-ng
Purl
pkg:deb/debian/lemonldap-ng?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.0.2+ds-7+deb10u1
Ecosystem specific
{ "urgency": "not yet assigned" }
Git
/
gitlab.ow2.org/lemonldap-ng/lemonldap-ng
Affected ranges
Type
GIT
Repo
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
651511a646fd26e6560be77f6c38185a8e77af9f
Affected versions
Other
debian/buster
ubuntu/disco
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
CVE-2019-12046 - OSV