An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Lemonldap-ng Lemonldap-ng lemonldap-ng | |
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:* | |
| Vendors & Products | Lemonldap-ng Lemonldap-ng lemonldap-ng | |
| Metrics | cvssV3_1 
 
 | 
Sun, 10 Nov 2024 22:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2024-11-10T00:00:00
Updated: 2024-11-19T19:34:45.685Z
Reserved: 2021-06-23T00:00:00
Link: CVE-2021-35473
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-19T19:29:31.821Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-11-10T23:15:04.383
Modified: 2024-11-19T20:35:13.347
Link: CVE-2021-35473
 Redhat
                        Redhat
                    No data.