[DSA 6434-1] lemonldap-ng security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6434-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 12, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : lemonldap-ng
CVE ID         : CVE-2026-12804 CVE-2026-19349

It was discovered that the Lemonldap::NG web SSO system insufficiently
enforced access when using the GitHub/Linkedin authentication backends.

For the stable distribution (trixie), these problems have been fixed in
version 2.21.2+ds-1+deb13u3.

We recommend that you upgrade your lemonldap-ng packages.

For the detailed security status of lemonldap-ng please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/lemonldap-ng

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmp8t7sACgkQEMKTtsN8
TjY+jhAArfNHY4PGLVgkmlE0HjdW1O/ZWMuTmQqdJGT8eGpUjztO+9GIWI/ZcU3M
j8RXwfTUN5+CS/xYo2rjzbM1XODncZVJN1l+8eVIS6YVDqWJiKb7Nmus+CBKXFGH
73ilkFTYMDWkPKrhr4BChtmcE+Xx3MREI2bXF36k6aTq3v4mfJh3TxLm/DsHh4ZQ
ukQHaGRKjsHZ1+Le92JeKKgs7k3WJbCrzTEhRBUevYQaPx8eRAQZfQpAY1b2ORyA
UqWZmv6482q7xka/DxrauGdu/Yg5PvR62s3n2Eypn7ZefH/ZMV2LrDtPg1n8+wZD
vps6NRfUiPZ1LZ8f7s/6BM1qE8tCIw5se56jipri4TnVE2UgkSTLi+hx4YYEMaut
AEtL9Gol+A9cMtVz6SNJHCHc6xn5tFf4yRCuAyN4DVJSjX1/u94fDTfYwjw3Ud1C
rpTPZFSOPXLIehwH40S7AxYiasbTEI1hQKv7eNNoWdcqZvtXTBHDzYG7jIg7QPjv
fg2wCsrvrYxBc6DuvtleXVXD2Prc+6JfkC1oIk5OowE0tw0HcenyFceGsPaLodsz
eR0G/JmuZP8ifmnqQdj/0IAyVUS/Epjm/HCw7qzbwPP0bwt711eAGQMM75lPcQwN
VVVx5p+55qrMdCgjbF9Y4UHB6EJRHudXLQIAG4gDLt+k73LyOFk=
=RXh0
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.