CVE-2024-45160

CRITICAL EPSS 39.9%
Published Oct 9, 20241y ago · Modified Jun 17, 20262w ago
9.1 CVSS 3.1
Critical
Find Similar
Published Oct 9, 2024 1y ago
Last Modified Jun 17, 2026 2w ago

Description

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

CVSS Details

Base Score
9.1
Exploitability
3.9
Impact
5.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None

Threat Intelligence

EPSS Exploit Probability
39.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-863 Incorrect Authorization Authorization

References 5

  • gitlab.ow2.org https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/06d771cbc2d5c752354c50f83e4912e5879f9aa2
  • gitlab.ow2.org https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/236cdfe42c1dc04a15a4a40c5e6a8c2e858d71d7
  • gitlab.ow2.org https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/696f49a0855faeb271096dccb8381e2129687c3d
  • gitlab.ow2.org https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3223
  • gitlab.ow2.org https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/tags

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.