CVE-2012-6426
EPSS 0.25%
Description
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
How to fix CVE-2012-6426
To remediate CVE-2012-6426, upgrade the affected package to a fixed version below.
- Debian/lemonldap-ng—upgrade to 1.2.2-3 or later
Is CVE-2012-6426 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.2.2-3