ELA-1263-1 lemonldap-ng security update

Multiple XSS vulnerabilities

2024-11-30
Packagelemonldap-ng
Version2.0.2+ds-7+deb10u11 (buster)
Related CVEs CVE-2024-48933 CVE-2024-52947


Two Cross-site scripting (XSS) vulnerabilities were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to injection of arbitrary scripts or HTML content.



For Debian 10 buster, these problems have been fixed in version 2.0.2+ds-7+deb10u11.

We recommend that you upgrade your lemonldap-ng packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.