2024-12-08 03:06:42 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2024-52946",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-11-18T06:15:06.460",
"lastModified": "2024-11-21T18:15:13.120",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an \"Adaptative authentication rule\" with an increment instead of an absolute value."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en LemonLDAP::NG antes de la versi\u00f3n 2.20.1. Una comprobaci\u00f3n incorrecta durante la actualizaci\u00f3n de la sesi\u00f3n permite que un usuario autenticado aumente su nivel de autenticaci\u00f3n si el administrador configur\u00f3 una \"regla de autenticaci\u00f3n adaptativa\" con un incremento en lugar de un valor absoluto."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"references": [
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3255",
"source": "cve@mitre.org"
}
]
}