CVE-2022-37186
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/04/2023
Last modified:
06/02/2025
Description
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:* | 2.0.15 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15
- https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/59c781b393947663ad3bf26bad0581413dd6fae4
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2758
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.0.15
- https://lists.debian.org/debian-lts-announce/2023/01/msg00027.html



