Session Management Flaw in LemonLDAP::NG Affects User Authentication
CVE-2021-35472
8.8HIGH
What is CVE-2021-35472?
A vulnerability exists in LemonLDAP::NG prior to version 2.0.12 that can lead to session cache corruption. This issue allows an attacker to exploit authentication processes, potentially causing authorization bypass or impersonation of another user. By executing a series of rapid authentication requests, an attacker may find themselves authenticated as either of two different users, undermining the integrity of user sessions.
