Debian Patches
Status for lemonldap-ng/2.16.1+ds-deb12u10
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| javascript-path.patch | preserve javascript-common path | Xavier Guimard <x.guimard@free.fr> | not-needed | 2018-10-30 | ||
| Avoid-developer-tests.patch | Avoid some heavy developer tests | Xavier Guimard <x.guimard@free.fr> | not-needed | debian | 2016-12-26 | |
| fix-for-pod2man.diff | restore directory removed during import | Xavier Guimard <yadd@debian.org> | not-needed | 2020-03-29 | ||
| replace-api-doc-by-link.diff | replace api doc by external link api is a compiled webpage (swagger-codegen). Since there is now good Open-API doc generator in Debian archive, this doc is excluded and replaced by a link to upstream website |
Xavier Guimard <yadd@debian.org> | yes | 2020-05-06 | ||
| drop-network-test.patch | drop network test | Yadd <yadd@debian.org> | not-needed | 2023-03-29 | ||
| fix-jwt.patch | fix bad JWT header | Yadd <yadd@debian.org> | yes | 2025-01-20 | ||
| fix-OP-acr-parsing.patch | fix incorrect parsing of OP-provided acr Bug description: . * Configure Auth::OIDC with an OP that always returns acr: 1 in the ID token * Set oidcOPMetaDataOptionsAcrValues to loa-1 ACR value 1 is accepted despite not being part of the list ['loa-1'] . The problem is in this regexp: . unless ( $acr_values =~ /\b$acr\b/i ) { . because \b matches too many things (in the example: it matches -) |
Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, commit: 3691978f | 2023-05-09 |
| fix-viewer-endpoint.patch | fix viewer endpoint Regression introduced in 2.16.1 | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, commit:c330347f | 2023-05-09 |
| apply-user-control-to-authslave.patch | [Security] apply user-control to authSlave | Christophe Maudoux <chrmdx@gmail.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/351/diffs | 2023-09-01 |
| fix-open-redirection.patch | fix open redirection Maxime Besson <maxime.besson@worteks.com> | Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/342/diffs | 2023-09-01 |
| fix-open-redirection-without-OIDC-redirect-uris.patch | Fix open redirection when OIDC RP has no oidcRPMetaDataOptionsRedirectUris This issue concerns only people that modify config by hand. The manager refuses already a relying party without redirect URIs. |
Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:c1de35ad | 2023-09-20 |
| SSRF-issue.patch | fix SSRF vulnerability Issue described here: https://security.lauritz-holtmann.de/post/sso-security-ssrf/ | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/383/diffs | 2023-09-22 |
| CVE-2024-48933.patch | Fix XSS vulnerability A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters. |
Maxime Besson | not-needed | debian upstream | 2024-10-15 | |
| fix-auth-level-escalation.patch | Do not run adaptativeAuthenticationLevel during refresh | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/5df0f833 | 2024-11-09 |
| fix-xss-in-upgrade-plugin.patch | Check XSS in ::Plugins::Upgrade | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/614 | 2024-11-09 |
| CVE-2024-52948.patch | fix CSRF on 2FA registration | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/644 | 2025-01-22 |
| fix-test-when-ldap-server-exists.patch | fix test when a LDAP server is run on build machine | Christophe Maudoux <chrmdx@gmail.com> | not-needed | 2025-02-02 | ||
| CVE-2025-31510.patch | fix XSS/HTML Injection through tab parameter (Choice) An input validation vulnerability has been identified in the tab parameter when authentication is set to Choice. This issue allows for the injection of malicious content, including HTML, iframes, or JavaScript, with varying impacts depending on the applied Content Security Policy (CSP) configuration. |
Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/a790b15e9 | 2025-03-29 |
| fix-bad-table-name.patch | fix fixed tablename | Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/d9db2a6b | 2025-07-12 |
| fix-oidc-fixed-server-in-case-of-error.patch | fix "when Auth::OpenIDConnect returns an error, the user cannot try again" | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/762 | 2025-07-12 |
| fix-kerberos-js.patch | make Kerberos module not submit form in case of error in choice menu | Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/752 | 2025-07-12 |
| improve-cors.patch | improve CORS checks | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/767 | 2025-07-12 |
| fix-path-info.patch | fix path_info | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/763 | 2025-07-12 |
| CVE-2025-59518.patch | fix admin shell injection | Maxime Bessons <maxime.besson@worteks.com> | not-needed | upstream | upstream, commit:37116d09f | 2025-10-17 |
| dont-expose-session-id-in-ajax-responses.patch | don't expose session id into Ajax responses | Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/778 | 2025-10-18 |
| workaround-nginx-issue.patch | workaround Nginx issue This patch is a supplementary security for the Nginx issue fixed in Nginx 1.26.3-3+deb13u4 . This avoids using the unsecure $http_host variable. |
Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:b82e1abd | 2026-09-01 |
| CVE-2026-12804.patch | Improve CDC filtering | Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/994 | |
| CVE-2026-19349.patch | use OTP for GitHub and LinkedIn states In LemonLDAP::NG 2.0.0 through 2.23.2, the GitHub and LinkedIn authentication backends store the OAuth2 state parameter using an obsolete positional call to getApacheSession(). The trailing arguments are silently misparsed as a named-argument hash, so the session kind defaults to SSO and the state is written to the global session storage as a regular SSO session. |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/1036 | 2026-08-08 |
| 3701-password-reveal-surrounding-form.patch | password reveal button only affects surrounding form The reveal button changed every input with the same name in the page, and only restored the first one: with browsersDontStorePassword, passwords typed in other forms of the portal could stay displayed in clear text. diff --git a/lemonldap-ng-portal/site/coffee/portal.coffee b/lemonldap-ng-portal/site/coffee/portal.coffee index 1346995..4a81646 100644 |
Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/ed6792384ad524b81f77458310cc33cf7f8edf40 | 2026-09-25 |
| 3701-match-all-password-forms.patch | match all password forms when hiding Password masking (browsersDontStorePassword) used "#id" selectors that only match the first element: when several forms share the same field id (auth choice, password change), passwords were displayed in clear text. diff --git a/lemonldap-ng-portal/site/coffee/portal.coffee b/lemonldap-ng-portal/site/coffee/portal.coffee index 4a81646..62673b7 100644 |
Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/40eb780778eeb663a3129623ebcf13918d11d55a | 2026-09-25 |
| 3722-force-scalar-context-for-params.patch | force scalar context for request parameters $req->param() was called in list context inside hash constructors: sending a parameter several times shifted keys and values, allowing an attacker to inject arbitrary keys (RESTProxy/SOAP server data, spoofId, templates). diff --git a/lemonldap-ng-portal/lib/Lemonldap/NG/Portal/Lib/RESTProxy.pm b/lemonldap-ng-portal/lib/Lemonldap/NG/Portal/Lib/RESTProxy.pm index 90c8fde..0d96105 100644 |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/56b209d4e34fc2e53c3bc19bb62a61f4d24edf3b | 2026-09-25 |
| 3726-pass-vhost-to-getLevel.patch | pass vhost to getLevel() in grant() When checking another virtual host (menu, REST/SOAP authorizationfor, CheckUser), the authentication level of the current vhost was used instead of the target one: apps requiring a higher level were reported as allowed. diff --git a/lemonldap-ng-handler/lib/Lemonldap/NG/Handler/Main/Run.pm b/lemonldap-ng-handler/lib/Lemonldap/NG/Handler/Main/Run.pm index 92f5a69..544d58f 100644 |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/b8229f302ef262b3078aa6125ef4cb347d4fba00 | 2026-09-25 |
| CVE-2026-95811.patch | test locationRules against the canonical URL Rules were tested against the raw REQUEST_URI while web servers route on the decoded and normalized path: rules could be bypassed with percent-encoded or dot-segment URLs (ie /my%73ession, /./admin). diff --git a/doc/sources/admin/security.rst b/doc/sources/admin/security.rst index 6076705..93d4259 100644 |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/682e1e6f3ded59fef015840b2f8d192bea0eec2f | 2026-09-25 |
All known versions for source package 'lemonldap-ng'
- 2.23.4+ds-1 (sid)
- 2.23.2+ds-1~bpo13+1 (trixie-backports)
- 2.21.3+ds-1~bpo12+1 (bookworm-backports)
- 2.21.2+ds-1+deb13u4 (trixie-security, trixie-proposed-updates)
- 2.21.2+ds-1+deb13u3 (trixie)
- 2.16.1+ds-deb12u10 (bookworm-security)
- 2.16.1+ds-deb12u8 (bookworm)
