In LemonLDAP::NG (aka lemonldap-ng) through 2.0.8, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://lemonldap-ng.org/download | vendor advisory |
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2250 | patch exploit third party advisory issue tracking |
https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html | third party advisory mailing list |