-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4734-1 [email protected]
https://www.debian.org/lts/security/ Xavier Guimard
August 12, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : lemonldap-ng
Version : 2.0.11+ds-4+deb11u9 2.16.1+ds-deb12u9
CVE ID : CVE-2026-12804 CVE-2026-19349
It was discovered that the Lemonldap::NG web SSO system insufficiently
enforced access when using the GitHub/Linkedin authentication backends.
CVE-2026-12804
A vulnerability was detected in lemonldap-ng up to 2.0.0. Impacted
is a function in the library
lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the
component SAML Common Domain Cookie Endpoint. Performing a
manipulation of the argument url results in open redirect.
CVE-2026-19349
A vulnerability was detected in lemonldap-ng up to 2.0.3 through
2.23.2, the GitHub and LinkedIn authentication backends store the
OAuth2 state parameter using an obsolete positional call to
getApacheSession(). The trailing arguments are silently misparsed
as a named-argument hash, so the session kind defaults to SSO and
the state is written to the global session storage as a regular
SSO session. Because the state value is handed to the
unauthenticated visitor in the redirection URL to the identity
provider, a remote attacker can replay it as a lemonldap session
cookie and obtain a valid SSO session without ever authenticating.
Only configurations in which the GitHub or LinkedIn authentication
module is enabled are affected.
For Debian 11 bullseye, these problems have been fixed in version
2.0.11+ds-4+deb11u9.
For Debian 12 bookworm, these problems have been fixed in version
2.16.1+ds-deb12u9.
We recommend that you upgrade your lemonldap-ng packages.
For the detailed security status of lemonldap-ng please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/lemonldap-ng
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmqWzDAACgkQDTl9HeUl
XjDheA/+OFnsEp2f444Izh/eI40bT0i3xBBBjMyxB39JMKLlCS/8ZcUovQSUDnR6
CeT0zeH5zoAYeRWAmraOFyt334AvvPYPqyM3WakHNWevH85EjP0uct5c3YivjmBC
2BSuij56mpvuxLSMqTelqKsy9KmQ71MUJSwXVTCEe14QXy/hYGt/UJBacXUYlHSh
2AbWLa9qFewoLR1+mFAyxrHQSj2expeHKSf5QJrRt/FQ9usGdlYlMYYQ4Ym7wVhy
NKTmtnbsN0vvgx6Dt7ZrkxMqCMwr0Nast1440hhQRC8rfjXlc8EQI/Tay6bNWEqz
tz2iHA4aDTf2dvckhf0im2fGyqB8cs/otqLOukLz4uKoZ+shOAC8rXeXgANXNaMt
pzfbmbFsA5dxPKpT+h1CFtFQYL6pEleAKtsaklvoxWKcDuHx+WYNy54XZLLTWOFJ
N8ng59SzxWr2vp61ew+gqOKpNuTZJeHOQadi0Dsx7z+xtu9xJkAhlEsLPR6V7PoZ
3mfbsRUL4S19fXqN87p3oQ6UNtBu90mwGMSaFJuIkMQXIg+bfSSJkNPq/u6d9q0h
qrGVrg55l7HWNcipdlTfuCJlJ0i5HTgW84tvyx625vQLvHyd57rvYMiFYU0/RylB
wFMQ5xCn8j/t4uXyh+7/oOEOs0+3PWFRhnq7oJkxsaMvQVtP8Wg=
=/hYj
-----END PGP SIGNATURE-----