CVE-2019-15941
Last modified
CVE-2019-15941 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access control rules than the target RP, and no filtering on redirection URIs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Lemonldap-Ng | Lemonldap\ | >= 2.0.0, <= 2.0.5 | Ng |
| Debian | Debian Linux | 10.0 | — |
References
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1881Third Party Advisory
- https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-6-is-out/Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/46Mailing List, Third Party Advisory
- https://www.debian.org/security/2019/dsa-4533Third Party Advisory
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1881Third Party Advisory
- https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-6-is-out/Third Party Advisory
- https://seclists.org/bugtraq/2019/Sep/46Mailing List, Third Party Advisory
- https://www.debian.org/security/2019/dsa-4533Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15941?
How severe is CVE-2019-15941?
How do I fix CVE-2019-15941?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15936Intesync Solismed 3.3sp allows Insecure File Upload.9.8
- CVE-2019-15937Pengutronix barebox through 2019.08.1 has a remote buffer ov…
- CVE-2019-15938Pengutronix barebox through 2019.08.1 has a remote buffer ov…
- CVE-2019-15939An issue was discovered in OpenCV 4.1.0. There is a divide-b…5.9
- CVE-2019-1594A vulnerability in the 802.1X implementation for Cisco NX-OS…7.4
- CVE-2019-15940Victure PC530 devices allow unauthenticated TELNET access as…9.8
- CVE-2019-15942FFmpeg through 4.2 has a "Conditional jump or move depends o…8.8
- CVE-2019-15943vphysics.dll in Counter-Strike: Global Offensive before 1.37…8.8
- CVE-2019-15944In Counter-Strike: Global Offensive before 8/29/2019, commun…5.3
- CVE-2019-15945OpenSC before 0.20.0-rc1 has an out-of-bounds access of an A…6.4
- CVE-2019-15946OpenSC before 0.20.0-rc1 has an out-of-bounds access of an A…6.4
- CVE-2019-15947In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data un…7.5
Are you affected by CVE-2019-15941?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
