-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4734-1               [email protected]
https://www.debian.org/lts/security/                      Xavier Guimard
August 12, 2026                              https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : lemonldap-ng
Version        : 2.0.11+ds-4+deb11u9 2.16.1+ds-deb12u9
CVE ID         : CVE-2026-12804 CVE-2026-19349

It was discovered that the Lemonldap::NG web SSO system insufficiently
enforced access when using the GitHub/Linkedin authentication backends.

CVE-2026-12804

      A vulnerability was detected in lemonldap-ng up to 2.0.0. Impacted
      is a function in the library
      lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the
      component SAML Common Domain Cookie Endpoint. Performing a
      manipulation of the argument url results in open redirect.

CVE-2026-19349

      A vulnerability was detected in lemonldap-ng up to 2.0.3 through
      2.23.2, the GitHub and LinkedIn authentication backends store the
      OAuth2 state parameter using an obsolete positional call to
      getApacheSession(). The trailing arguments are silently misparsed
      as a named-argument hash, so the session kind defaults to SSO and
      the state is written to the global session storage as a regular
      SSO session. Because the state value is handed to the
      unauthenticated visitor in the redirection URL to the identity
      provider, a remote attacker can replay it as a lemonldap session
      cookie and obtain a valid SSO session without ever authenticating.
      Only configurations in which the GitHub or LinkedIn authentication
      module is enabled are affected.

For Debian 11 bullseye, these problems have been fixed in version
2.0.11+ds-4+deb11u9.

For Debian 12 bookworm, these problems have been fixed in version
2.16.1+ds-deb12u9.

We recommend that you upgrade your lemonldap-ng packages.

For the detailed security status of lemonldap-ng please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/lemonldap-ng

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmqWzDAACgkQDTl9HeUl
XjDheA/+OFnsEp2f444Izh/eI40bT0i3xBBBjMyxB39JMKLlCS/8ZcUovQSUDnR6
CeT0zeH5zoAYeRWAmraOFyt334AvvPYPqyM3WakHNWevH85EjP0uct5c3YivjmBC
2BSuij56mpvuxLSMqTelqKsy9KmQ71MUJSwXVTCEe14QXy/hYGt/UJBacXUYlHSh
2AbWLa9qFewoLR1+mFAyxrHQSj2expeHKSf5QJrRt/FQ9usGdlYlMYYQ4Ym7wVhy
NKTmtnbsN0vvgx6Dt7ZrkxMqCMwr0Nast1440hhQRC8rfjXlc8EQI/Tay6bNWEqz
tz2iHA4aDTf2dvckhf0im2fGyqB8cs/otqLOukLz4uKoZ+shOAC8rXeXgANXNaMt
pzfbmbFsA5dxPKpT+h1CFtFQYL6pEleAKtsaklvoxWKcDuHx+WYNy54XZLLTWOFJ
N8ng59SzxWr2vp61ew+gqOKpNuTZJeHOQadi0Dsx7z+xtu9xJkAhlEsLPR6V7PoZ
3mfbsRUL4S19fXqN87p3oQ6UNtBu90mwGMSaFJuIkMQXIg+bfSSJkNPq/u6d9q0h
qrGVrg55l7HWNcipdlTfuCJlJ0i5HTgW84tvyx625vQLvHyd57rvYMiFYU0/RylB
wFMQ5xCn8j/t4uXyh+7/oOEOs0+3PWFRhnq7oJkxsaMvQVtP8Wg=
=/hYj
-----END PGP SIGNATURE-----

Reply via email to