empty client_password parameter bypasses OAuth2 client authentication
CVE-2024-45160
9.1CRITICAL
What is CVE-2024-45160?
A security issue has been identified in LemonLDAP::NG versions 2.18.x and 2.19.x prior to 2.19.2, where incorrect credential validation allows an attacker to bypass OAuth2 client authentication. This can be achieved by sending an empty client_password parameter, potentially compromising the authentication process and granting unauthorized access.
