CVE-2024-45160: Lemonldap-NG

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

Affected products

  • Lemonldap-NG Lemonldap-NG: from 2.18.0, before 2.19.2 (fixed in 2.19.2)

Published 2024-10-09. Last modified 2026-06-17.