cve/2024/CVE-2024-45160.md
2025-09-29 21:09:30 +02:00

751 B

CVE-2024-45160

Description

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

POC

Reference

No PoCs from references.

Github