Debian Patches

Status for lemonldap-ng/2.21.2+ds-1+deb13u4

Patch Description Author Forwarded Bugs Origin Last update
javascript-path.patch preserve javascript-common path Xavier Guimard <x.guimard@free.fr> not-needed 2018-10-30
Avoid-developer-tests.patch Avoid some heavy developer tests Xavier Guimard <x.guimard@free.fr> not-needed debian 2016-12-26
replace-api-doc-by-link.diff replace api doc by external link api is a compiled webpage (swagger-codegen). Since there is now good
Open-API doc generator in Debian archive, this doc is excluded and
replaced by a link to upstream website
Xavier Guimard <yadd@debian.org> yes 2020-05-06
fix-makefile.patch fix makefile (shuffle bug) Yadd <yadd@debian.org> yes debian 2025-05-13
CVE-2025-59518.patch fix shell injection from admin interface (notifications Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, commit:228d0194, commit:8b5ce4de 2025-10-17
dont-expose-session-id-in-ajax-responses.patch don't expose session id into Ajax responses Yadd <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/778 2025-09-12
fix-google-auth.patch fix Google OIDC authentication Maxime Besson <maxime.besson@worteks.com not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/777 2025-09-12
3478-fix-oidc-alg.patch fix typo that breaks alg Sadly the test OP was named "op" Yadd <yadd@debian.org> not-needed upstream 2026-09-01
really-hide-password-in-session-explorer.patch really hide passwords from session explorer Yadd <yadd@debian.org> not-needed upstream upstream, commit:d9ba579 2026-09-01
fix-oidc-frontchannel.patch fix typo that broke OIDC front-channel-logout Yadd <yadd@debian.org> not-needed upstream upstream, commit:c4dde51 2026-09-01
workaround-nginx-issue.patch workaround Nginx issue This patch is a supplementary security for the Nginx issue fixed in Nginx
1.26.3-3+deb13u4
.
This avoids using the unsecure $http_host variable.
Yadd <yadd@debian.org> not-needed upstream upstream, commit:b82e1abd 2026-09-01
CVE-2026-19349.patch use OTP for GitHub and LinkedIn states In LemonLDAP::NG 2.0.0 through 2.23.2, the GitHub and
LinkedIn authentication backends store the OAuth2 state
parameter using an obsolete positional call to
getApacheSession(). The trailing arguments are silently
misparsed as a named-argument hash, so the session kind
defaults to SSO and the state is written to the global
session storage as a regular SSO session.
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/1036 2026-08-08
CVE-2026-12804.patch Improve CDC filtering Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/994
3701-password-reveal-surrounding-form.patch password reveal button only affects surrounding form The reveal button changed every input with the same name in the page, and
only restored the first one: with browsersDontStorePassword, passwords typed
in other forms of the portal could stay displayed in clear text.
Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/f082d6a0dc8ef18178f2c6965bd2c3f8d07aded0 2026-09-24
3701-match-all-password-forms.patch match all password forms when hiding Password masking (browsersDontStorePassword) used "#id" selectors that only
match the first element: when several forms share the same field id (auth
choice, password change), passwords were displayed in clear text.
Maxime Besson <maxime.besson@worteks.com> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/7e234410aa9a087a7531cfa1d43966352837c17b 2026-09-24
3722-force-scalar-context-for-params.patch force scalar context for request parameters $req->param() was called in list context inside hash constructors: sending
a parameter several times shifted keys and values, allowing an attacker to
inject arbitrary keys (token exchange session data, spoofId, templates).
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/c2ffa8e4e64a02d0783757c6fa0c96d1f8340063 2026-09-24
3726-pass-vhost-to-getLevel.patch pass vhost to getLevel() in grant() When checking another virtual host (menu, REST/SOAP authorizationfor,
CheckUser), the authentication level of the current vhost was used instead
of the target one: apps requiring a higher level were reported as allowed.
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/8bc05c2422aaddd699d46d4f5bcff600237262e6 2026-09-24
CVE-2026-95811.patch test locationRules against the canonical URL Rules were tested against the raw REQUEST_URI while web servers route on the
decoded and normalized path: rules could be bypassed with percent-encoded or
dot-segment URLs (ie /my%73ession, /./admin).
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/e5b082c76468b317d8de4b739420b609b633e71e 2026-09-24
CVE-2026-92288-CVE-2026-92289.patch check client secret of public OIDC clients The secret of public clients was never checked but they were considered as
authenticated with client_secret_*: anyone knowing a client_id could use the
introspection endpoint and get token data including the user identifier.
Xavier Guimard <yadd@debian.org> not-needed upstream upstream, https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/458c155707b06e68535dea85fc21bfd4ba2bbde3 2026-09-24

All known versions for source package 'lemonldap-ng'

Links