Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LemonLDAP::NG 安全漏洞
Vulnerability Description
LemonLDAP::NG是LemonLDAP::NG开源的一套Web单点登录和访问管理软件。 LemonLDAP::NG 2.18.x版本和2.19.2之前的2.19.x版本存在安全漏洞,该漏洞源于存在不正确的凭据验证,允许攻击者通过空client_password参数绕过OAuth2客户端认证。
CVSS Information
N/A
Vulnerability Type
N/A