Session Management Flaw in LemonLDAP::NG Affects Open Source Identity Management
CVE-2022-37186
5.9MEDIUM
What is CVE-2022-37186?
In LemonLDAP::NG, there is a flaw in the session management process where certain sessions may not be deleted as expected based on the configured timeoutActivity setting. This issue arises particularly when multiple servers are involved, and a session is manually removed prior to its scheduled automatic deletion. Such behavior could lead to unauthorized access or lingering sessions, posing a risk to the security of the application and its users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
