CVE-2022-37186

In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a session is manually removed before the time at which it would have been removed automatically.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-04-16 02:15

Updated : 2024-02-28 20:13


NVD link : CVE-2022-37186

Mitre link : CVE-2022-37186

CVE.ORG link : CVE-2022-37186


JSON object : View

Products Affected

lemonldap-ng

  • lemonldap\
CWE
CWE-613

Insufficient Session Expiration