An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 21 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Lemonldap-ng Lemonldap-ng lemonldap-ng | |
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:lemonldap-ng:lemonldap-ng:*:*:*:*:*:*:*:* | |
| Vendors & Products | Lemonldap-ng Lemonldap-ng lemonldap-ng | |
| Metrics | cvssV3_1 
 
 | 
Mon, 18 Nov 2024 06:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value. | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2024-11-18T00:00:00
Updated: 2024-11-21T17:06:21.816Z
Reserved: 2024-11-18T00:00:00
Link: CVE-2024-52946
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-21T17:06:16.041Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-11-18T06:15:06.460
Modified: 2024-11-21T18:15:13.120
Link: CVE-2024-52946
 Redhat
                        Redhat
                    No data.