CVE-2020-36658: Debian Linux

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Lemonldap-NG Apache::session::ldap: before 0.5 (fixed in 0.5)

Published 2023-01-27. Last modified 2026-06-17.