Beveiligingsadvies

CVE-2024-45160

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-10-09 00:00:00
Laatst bijgewerkt 2024-10-09 20:50:54
Toegewezen door mitre
CVSS-score 9.1
Status PUBLISHED

Beschrijving

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).