Debian Patches
Status for lemonldap-ng/2.21.2+ds-1+deb13u4
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| javascript-path.patch | preserve javascript-common path | Xavier Guimard <x.guimard@free.fr> | not-needed | 2018-10-30 | ||
| Avoid-developer-tests.patch | Avoid some heavy developer tests | Xavier Guimard <x.guimard@free.fr> | not-needed | debian | 2016-12-26 | |
| replace-api-doc-by-link.diff | replace api doc by external link api is a compiled webpage (swagger-codegen). Since there is now good Open-API doc generator in Debian archive, this doc is excluded and replaced by a link to upstream website |
Xavier Guimard <yadd@debian.org> | yes | 2020-05-06 | ||
| fix-makefile.patch | fix makefile (shuffle bug) | Yadd <yadd@debian.org> | yes | debian | 2025-05-13 | |
| CVE-2025-59518.patch | fix shell injection from admin interface (notifications | Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, commit:228d0194, commit:8b5ce4de | 2025-10-17 |
| dont-expose-session-id-in-ajax-responses.patch | don't expose session id into Ajax responses | Yadd <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/778 | 2025-09-12 |
| fix-google-auth.patch | fix Google OIDC authentication | Maxime Besson <maxime.besson@worteks.com | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/777 | 2025-09-12 |
| 3478-fix-oidc-alg.patch | fix typo that breaks alg Sadly the test OP was named "op" | Yadd <yadd@debian.org> | not-needed | upstream | 2026-09-01 | |
| really-hide-password-in-session-explorer.patch | really hide passwords from session explorer | Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:d9ba579 | 2026-09-01 |
| fix-oidc-frontchannel.patch | fix typo that broke OIDC front-channel-logout | Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:c4dde51 | 2026-09-01 |
| workaround-nginx-issue.patch | workaround Nginx issue This patch is a supplementary security for the Nginx issue fixed in Nginx 1.26.3-3+deb13u4 . This avoids using the unsecure $http_host variable. |
Yadd <yadd@debian.org> | not-needed | upstream | upstream, commit:b82e1abd | 2026-09-01 |
| CVE-2026-19349.patch | use OTP for GitHub and LinkedIn states In LemonLDAP::NG 2.0.0 through 2.23.2, the GitHub and LinkedIn authentication backends store the OAuth2 state parameter using an obsolete positional call to getApacheSession(). The trailing arguments are silently misparsed as a named-argument hash, so the session kind defaults to SSO and the state is written to the global session storage as a regular SSO session. |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/1036 | 2026-08-08 |
| CVE-2026-12804.patch | Improve CDC filtering | Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/994 | |
| 3701-password-reveal-surrounding-form.patch | password reveal button only affects surrounding form The reveal button changed every input with the same name in the page, and only restored the first one: with browsersDontStorePassword, passwords typed in other forms of the portal could stay displayed in clear text. |
Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/f082d6a0dc8ef18178f2c6965bd2c3f8d07aded0 | 2026-09-24 |
| 3701-match-all-password-forms.patch | match all password forms when hiding Password masking (browsersDontStorePassword) used "#id" selectors that only match the first element: when several forms share the same field id (auth choice, password change), passwords were displayed in clear text. |
Maxime Besson <maxime.besson@worteks.com> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/7e234410aa9a087a7531cfa1d43966352837c17b | 2026-09-24 |
| 3722-force-scalar-context-for-params.patch | force scalar context for request parameters $req->param() was called in list context inside hash constructors: sending a parameter several times shifted keys and values, allowing an attacker to inject arbitrary keys (token exchange session data, spoofId, templates). |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/c2ffa8e4e64a02d0783757c6fa0c96d1f8340063 | 2026-09-24 |
| 3726-pass-vhost-to-getLevel.patch | pass vhost to getLevel() in grant() When checking another virtual host (menu, REST/SOAP authorizationfor, CheckUser), the authentication level of the current vhost was used instead of the target one: apps requiring a higher level were reported as allowed. |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8bc05c2422aaddd699d46d4f5bcff600237262e6 | 2026-09-24 |
| CVE-2026-95811.patch | test locationRules against the canonical URL Rules were tested against the raw REQUEST_URI while web servers route on the decoded and normalized path: rules could be bypassed with percent-encoded or dot-segment URLs (ie /my%73ession, /./admin). |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/e5b082c76468b317d8de4b739420b609b633e71e | 2026-09-24 |
| CVE-2026-92288-CVE-2026-92289.patch | check client secret of public OIDC clients The secret of public clients was never checked but they were considered as authenticated with client_secret_*: anyone knowing a client_id could use the introspection endpoint and get token data including the user identifier. |
Xavier Guimard <yadd@debian.org> | not-needed | upstream | upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/458c155707b06e68535dea85fc21bfd4ba2bbde3 | 2026-09-24 |
All known versions for source package 'lemonldap-ng'
- 2.23.4+ds-1 (sid)
- 2.23.2+ds-1~bpo13+1 (trixie-backports)
- 2.21.3+ds-1~bpo12+1 (bookworm-backports)
- 2.21.2+ds-1+deb13u4 (trixie-security, trixie-proposed-updates)
- 2.21.2+ds-1+deb13u3 (trixie)
- 2.16.1+ds-deb12u10 (bookworm-security)
- 2.16.1+ds-deb12u8 (bookworm)
