Fedora 40: lemonldap-ng 2024-e457192aa2 Security Advisory Updates
Summary
LemonLdap::NG is a modular Web-SSO based on Apache::Session modules. It
simplifies the build of a protected area with a few changes in the
application. It manages both authentication and authorization and provides
headers for accounting.
So you can have a full AAA protection for your web space as described below.
Update Information:
Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by "Refresh my rights" [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid "This application is not known" when trying to access a federation application with empty RelayState SAML regression in 2.20.0 Internal error when captcha rule isn't validated
Change Log
* Fri Nov 8 2024 Clement Oudot
References
Fedora Update Notification FEDORA-2024-e457192aa2 2024-11-19 01:21:30.375627 Name : lemonldap-ng Product : Fedora 40 Version : 2.20.1 Release : 1.fc40 URL : https://lemonldap-ng.org Summary : Web Single Sign On (SSO) and Access Management Description : LemonLdap::NG is a modular Web-SSO based on Apache::Session modules. It simplifies the build of a protected area with a few changes in the application. It manages both authentication and authorization and provides headers for accounting. So you can have a full AAA protection for your web space as described below.
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e457192aa2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label