Debian Security Update DSA-5897-1 lemonldap-ng - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,819
Reaction score
74
Credits
-1,257
A cross-site scripting vulnerability has been discovered in Lemonldap::NG, a Web-SSO system compatible with OpenID-Connect, CAS and SAML, when using the "Choice" module: It permits to introduce HTML code into the login page and if the default Content-Security-Policy headers have been modified, it may be possible to inject JavaScript code.
https://security-tracker.debian.org/tracker/DSA-5897-1

Continue reading...
 


Follow Linux.org

Members online


Top