Debian Patches
Status for lemonldap-ng/2.21.2+ds-1+deb13u3
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| javascript-path.patch | preserve javascript-common path | Xavier Guimard <x.guimard@free.fr> | not-needed | 2018-10-30 | ||
| Avoid-developer-tests.patch | Avoid some heavy developer tests | Xavier Guimard <x.guimard@free.fr> | not-needed | debian | 2016-12-26 | |
| replace-api-doc-by-link.diff | replace api doc by external link api is a compiled webpage (swagger-codegen). Since there is now good Open-API doc generator in Debian archive, this doc is excluded and replaced by a link to upstream website |
Xavier Guimard <yadd@debian.org> | yes | 2020-05-06 | ||
| fix-makefile.patch | fix makefile (shuffle bug) | Yadd <yadd@debian.org> | yes | debian | 2025-05-13 | |
| CVE-2025-59518.patch | fix shell injection from admin interface (notifications | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, commit:228d0194, commit:8b5ce4de | 2025-10-17 |
| dont-expose-session-id-in-ajax-responses.patch | don't expose session id into Ajax responses | Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/778 | 2025-09-12 |
| fix-google-auth.patch | fix Google OIDC authentication | Maxime Besson <maxime.besson@worteks.com | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/777 | 2025-09-12 |
| 3478-fix-oidc-alg.patch | fix typo that breaks alg Sadly the test OP was named "op" | Yadd <yadd@debian.org> | not-needed | upstream | 2026-08-01 | |
| really-hide-password-in-session-explorer.patch | really hide passwords from session explorer | Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:d9ba579 | 2026-08-01 |
| fix-oidc-frontchannel.patch | fix typo that broke OIDC front-channel-logout | Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:c4dde51 | 2026-08-01 |
| workaround-nginx-issue.patch | workaround Nginx issue This patch is a supplementary security for the Nginx issue fixed in Nginx 1.26.3-3+deb13u4 . This avoids using the unsecure $http_host variable. |
Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:b82e1abd | 2026-08-01 |
| CVE-2026-19349.patch | use OTP for GitHub and LinkedIn states In LemonLDAP::NG 2.0.0 through 2.23.2, the GitHub and LinkedIn authentication backends store the OAuth2 state parameter using an obsolete positional call to getApacheSession(). The trailing arguments are silently misparsed as a named-argument hash, so the session kind defaults to SSO and the state is written to the global session storage as a regular SSO session. |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/1036 | 2026-08-08 |
| CVE-2026-12804.patch | Improve CDC filtering | Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/994 |
All known versions for source package 'lemonldap-ng'
- 2.23.3+ds-1 (sid)
- 2.23.2+ds-1~bpo13+1 (trixie-backports)
- 2.21.3+ds-1~bpo12+1 (bookworm-backports)
- 2.21.2+ds-1+deb13u3 (trixie-security)
- 2.21.2+ds-1+deb13u2 (trixie)
- 2.16.1+ds-deb12u9 (bookworm-security)
- 2.16.1+ds-deb12u8 (bookworm)
