CVE-2012-6426: Lemonldap-NG Lemonldap::

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.

Affected products

  • Lemonldap-NG Lemonldap::: version 0.6 only; version 0.7 only; version 0.8 only; version 0.9 only; version 1.0 only
  • Lemonldap-NG Lemonldap::ng: up to and including 1.2.2; version 0.8.1 only; version 0.8.2 only; version 0.8.3 only; version 0.9.1 only; version 0.9.2 only; …

Published 2013-01-01. Last modified 2026-06-16.