Debian Patches

Status for lemonldap-ng/2.16.1+ds-deb12u10

Patch Description Author Forwarded Bugs Origin Last update
javascript-path.patch preserve javascript-common path Xavier Guimard <x.guimard@free.fr> not-needed 2018-10-30
Avoid-developer-tests.patch Avoid some heavy developer tests Xavier Guimard <x.guimard@free.fr> not-needed debian 2016-12-26
fix-for-pod2man.diff restore directory removed during import Xavier Guimard <yadd@debian.org> not-needed 2020-03-29
replace-api-doc-by-link.diff replace api doc by external link api is a compiled webpage (swagger-codegen). Since there is now good
Open-API doc generator in Debian archive, this doc is excluded and
replaced by a link to upstream website
Xavier Guimard <yadd@debian.org> yes 2020-05-06
drop-network-test.patch drop network test Yadd <yadd@debian.org> not-needed 2023-03-29
fix-jwt.patch fix bad JWT header Yadd <yadd@debian.org> yes 2025-01-20
fix-OP-acr-parsing.patch fix incorrect parsing of OP-provided acr Bug description:
.
* Configure Auth::OIDC with an OP that always returns acr: 1 in the ID token
* Set oidcOPMetaDataOptionsAcrValues to loa-1
ACR value 1 is accepted despite not being part of the list ['loa-1']
.
The problem is in this regexp:
.
unless ( $acr_values =~ /\b$acr\b/i ) {
.
because \b matches too many things (in the example: it matches -)
Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, commit: 3691978f 2023-05-09
fix-viewer-endpoint.patch fix viewer endpoint Regression introduced in 2.16.1 Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, commit:c330347f 2023-05-09
apply-user-control-to-authslave.patch [Security] apply user-control to authSlave Christophe Maudoux <chrmdx@gmail.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/351/diffs 2023-09-01
fix-open-redirection.patch fix open redirection Maxime Besson <maxime.besson@worteks.com> Yadd <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/342/diffs 2023-09-01
fix-open-redirection-without-OIDC-redirect-uris.patch Fix open redirection when OIDC RP has no oidcRPMetaDataOptionsRedirectUris This issue concerns only people that modify config by hand. The manager
refuses already a relying party without redirect URIs.
Yadd <yadd@debian.org> not-needed upstream upstream, commit:c1de35ad 2023-09-20
SSRF-issue.patch fix SSRF vulnerability Issue described here: https://security.lauritz-holtmann.de/post/sso-security-ssrf/ Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/383/diffs 2023-09-22
CVE-2024-48933.patch Fix XSS vulnerability A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3
allows remote attackers to inject arbitrary web script or HTML into the
login page via a username if userControl has been set to a non-default
value that allows special HTML characters.
Maxime Besson not-needed debian upstream 2024-10-15
fix-auth-level-escalation.patch Do not run adaptativeAuthenticationLevel during refresh Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/5df0f833 2024-11-09
fix-xss-in-upgrade-plugin.patch Check XSS in ::Plugins::Upgrade Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/614 2024-11-09
CVE-2024-52948.patch fix CSRF on 2FA registration Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/644 2025-01-22
fix-test-when-ldap-server-exists.patch fix test when a LDAP server is run on build machine Christophe Maudoux <chrmdx@gmail.com> not-needed 2025-02-02
CVE-2025-31510.patch fix XSS/HTML Injection through tab parameter (Choice) An input validation vulnerability has been identified in the tab parameter
when authentication is set to Choice.
This issue allows for the injection of malicious content, including HTML,
iframes, or JavaScript, with varying impacts depending on the applied
Content Security Policy (CSP) configuration.
Yadd <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/a790b15e9 2025-03-29
fix-bad-table-name.patch fix fixed tablename Yadd <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/d9db2a6b 2025-07-12
fix-oidc-fixed-server-in-case-of-error.patch fix "when Auth::OpenIDConnect returns an error, the user cannot try again" Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/762 2025-07-12
fix-kerberos-js.patch make Kerberos module not submit form in case of error in choice menu Yadd <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/752 2025-07-12
improve-cors.patch improve CORS checks Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/767 2025-07-12
fix-path-info.patch fix path_info Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/763 2025-07-12
CVE-2025-59518.patch fix admin shell injection Maxime Bessons <maxime.besson@worteks.com> not-needed upstream upstream, commit:37116d09f 2025-10-17
dont-expose-session-id-in-ajax-responses.patch don't expose session id into Ajax responses Yadd <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/778 2025-10-18
workaround-nginx-issue.patch workaround Nginx issue This patch is a supplementary security for the Nginx issue fixed in Nginx
1.26.3-3+deb13u4
.
This avoids using the unsecure $http_host variable.
Yadd <yadd@debian.org> not-needed upstream upstream, commit:b82e1abd 2026-09-01
CVE-2026-12804.patch Improve CDC filtering Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/994
CVE-2026-19349.patch use OTP for GitHub and LinkedIn states In LemonLDAP::NG 2.0.0 through 2.23.2, the GitHub and
LinkedIn authentication backends store the OAuth2 state
parameter using an obsolete positional call to
getApacheSession(). The trailing arguments are silently
misparsed as a named-argument hash, so the session kind
defaults to SSO and the state is written to the global
session storage as a regular SSO session.
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/1036 2026-08-08
3701-password-reveal-surrounding-form.patch password reveal button only affects surrounding form The reveal button changed every input with the same name in the page, and
only restored the first one: with browsersDontStorePassword, passwords typed
in other forms of the portal could stay displayed in clear text.

diff --git a/lemonldap-ng-portal/site/coffee/portal.coffee b/lemonldap-ng-portal/site/coffee/portal.coffee
index 1346995..4a81646 100644
Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/ed6792384ad524b81f77458310cc33cf7f8edf40 2026-09-25
3701-match-all-password-forms.patch match all password forms when hiding Password masking (browsersDontStorePassword) used "#id" selectors that only
match the first element: when several forms share the same field id (auth
choice, password change), passwords were displayed in clear text.

diff --git a/lemonldap-ng-portal/site/coffee/portal.coffee b/lemonldap-ng-portal/site/coffee/portal.coffee
index 4a81646..62673b7 100644
Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/40eb780778eeb663a3129623ebcf13918d11d55a 2026-09-25
3722-force-scalar-context-for-params.patch force scalar context for request parameters $req->param() was called in list context inside hash constructors: sending
a parameter several times shifted keys and values, allowing an attacker to
inject arbitrary keys (RESTProxy/SOAP server data, spoofId, templates).

diff --git a/lemonldap-ng-portal/lib/Lemonldap/NG/Portal/Lib/RESTProxy.pm b/lemonldap-ng-portal/lib/Lemonldap/NG/Portal/Lib/RESTProxy.pm
index 90c8fde..0d96105 100644
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/56b209d4e34fc2e53c3bc19bb62a61f4d24edf3b 2026-09-25
3726-pass-vhost-to-getLevel.patch pass vhost to getLevel() in grant() When checking another virtual host (menu, REST/SOAP authorizationfor,
CheckUser), the authentication level of the current vhost was used instead
of the target one: apps requiring a higher level were reported as allowed.

diff --git a/lemonldap-ng-handler/lib/Lemonldap/NG/Handler/Main/Run.pm b/lemonldap-ng-handler/lib/Lemonldap/NG/Handler/Main/Run.pm
index 92f5a69..544d58f 100644
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/b8229f302ef262b3078aa6125ef4cb347d4fba00 2026-09-25
CVE-2026-95811.patch test locationRules against the canonical URL Rules were tested against the raw REQUEST_URI while web servers route on the
decoded and normalized path: rules could be bypassed with percent-encoded or
dot-segment URLs (ie /my%73ession, /./admin).

diff --git a/doc/sources/admin/security.rst b/doc/sources/admin/security.rst
index 6076705..93d4259 100644
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/682e1e6f3ded59fef015840b2f8d192bea0eec2f 2026-09-25

All known versions for source package 'lemonldap-ng'

Links