Session Management Flaw in LemonLDAP::NG Affects Open Source Identity Management
CVE-2022-37186
5.9MEDIUM
What is CVE-2022-37186?
In LemonLDAP::NG, there is a flaw in the session management process where certain sessions may not be deleted as expected based on the configured timeoutActivity setting. This issue arises particularly when multiple servers are involved, and a session is manually removed prior to its scheduled automatic deletion. Such behavior could lead to unauthorized access or lingering sessions, posing a risk to the security of the application and its users.
