CVE-2024-52946

unknown
Published — · Modified —
CVSS v3
CVSS v2
VIR risk

Description

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-52946

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.16.1+ds-deb12u4
debian debianbullseyefixed2.0.11+ds-4+deb11u6
debian debianforkyfixed2.20.1+ds-1
debian debiansidfixed2.20.1+ds-1
debian debiantrixiefixed2.20.1+ds-1

References

Verify integrity in audit chain (admin only). AS-IS.