CVE-2024-52946

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 18, 2024
Updated: Nov 21, 2024
CWE ID 276

Summary

CVE-2024-52946 is a vulnerability affecting LemonLDAP::NG versions prior to 2.20.1. This issue involves an improper check during session refresh, enabling an authenticated user to elevate their authentication level. If an "Adaptative authentication rule" is configured with an increment instead of an absolute value by the admin, the user can exploit this vulnerability to increase their privileges. This can potentially lead to unauthorized access or other security breaches. It is highly recommended that affected organizations upgrade to the latest version of LemonLDAP::NG to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share