Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN942
_____________________________________________________________________

DATE                : 28/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running Lemonldap::NG::Portal versions
                                 prior to 2.21.6, 2.23.4,
                     Lemonldap-NG-Handler versions prior to 2.16.10,
                                     2.21.6, 2.23.4.
  
=====================================================================
https://lists.security.metacpan.org/cve-announce/msg/43830141/
https://lists.security.metacpan.org/cve-announce/msg/43830168/
https://lists.security.metacpan.org/cve-announce/msg/43833452/
_____________________________________________________________________

========================================================================
CVE-2026-92288                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-92288

   Distribution:  Lemonldap-NG-Portal
       Versions:  from 2.20.0 before 2.21.6
                  from 2.22.0 before 2.23.4
       MetaCPAN:  https://metacpan.org/dist/Lemonldap-NG-Portal
       VCS Repo:  https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0
before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection
because checkEndPointAuthenticationCredentials does not verify the
client secret of a public Relying Party

Description
-----------
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0
before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection
because checkEndPointAuthenticationCredentials does not verify the
client secret of a public Relying Party.

checkEndPointAuthenticationCredentials() skips the secret comparison
for a Relying Party marked public and still returns the authentication
method deduced from the request, client_secret_basic or
client_secret_post. introspection() rejects a caller only when that
method is missing or none, so a request carrying a public client_id and
an arbitrary or empty secret passes the endpoint's authentication
check.

An attacker who holds an access token and knows the client_id of any
public Relying Party can confirm the token is active and read its
metadata, including scope, audience, expiry and the sub claim. The sub
claim is computed with the calling Relying Party's user identifier
attribute, so an attacker can translate a user identifier from one
Relying Party to another, defeating per-client and pseudonymous
identifiers.

Problem types
-------------
- CWE-1390 Weak Authentication

Solutions
---------
Upgrade to Lemonldap-NG-Portal 2.21.6 or 2.23.4 or later. Only 2.23.4
is on CPAN; the 2.21.6 LTS release is available from
https://lemonldap-ng.org/download.html.

References
----------
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3721
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6
_____________________________________________________________________

========================================================================
CVE-2026-92289                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-92289

   Distribution:  Lemonldap-NG-Portal
       Versions:  from 2.23.0 before 2.23.4
       MetaCPAN:  https://metacpan.org/dist/Lemonldap-NG-Portal
       VCS Repo:  https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng

Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow
a PKCE bypass for public Relying Parties in "PKCE or secret" mode
because checkEndPointAuthenticationCredentials does not verify the
client secret

Description
-----------
Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow
a PKCE bypass for public Relying Parties in "PKCE or secret" mode
because checkEndPointAuthenticationCredentials does not verify the
client secret.

With oidcRPMetaDataOptionsRequirePKCE set to 2, the authorization
endpoint issues a code even when the request carries no code_challenge,
and token() admits the exchange as long as a challenge was stored or an
authentication method was returned for the caller.
checkEndPointAuthenticationCredentials() skips the secret comparison
for a Relying Party marked public and still returns the method deduced
from the request, so any Basic or form credential satisfies the secret
branch. validatePKCEChallenge() then passes, because neither a
challenge nor a verifier is present.

An attacker who intercepts an authorization code issued to a public
Relying Party can exchange it for the user's access, ID and refresh
tokens by replaying the client_id with an arbitrary secret, which is
the attack PKCE prevents. Dynamic client registration creates every
Relying Party in this mode.

Problem types
-------------
- CWE-1390 Weak Authentication

Workarounds
-----------
For deployments that cannot upgrade to 2.23.4, set RequirePKCE to 1 on
public Relying Parties so that a code challenge is always required.
Relying Parties created through dynamic registration are always in
"PKCE or secret" mode, so that endpoint has to be disabled as well.

Solutions
---------
Upgrade to Lemonldap-NG-Portal 2.23.4 or later.

References
----------
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3719
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4
_____________________________________________________________________

========================================================================
CVE-2026-95811                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-95811

   Distribution:  Lemonldap-NG-Handler
       Versions:  from 2.0.0 before 2.16.10
                  from 2.17.0 before 2.21.6
                  from 2.22.0 before 2.23.4
       MetaCPAN:  https://metacpan.org/dist/Lemonldap-NG-Handler
       VCS Repo:  https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng

Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0
before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent
spelling of a path to bypass the locationRules that restrict it

Description
-----------
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0
before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent
spelling of a path to bypass the locationRules that restrict it.

The handler matches each vhost's locationRules regular expressions
against REQUEST_URI, the raw request line, while the web server routes
on the path it has already percent-decoded and normalized. A request
that percent-encodes a character of the path, inserts dot segments, or
doubles a slash therefore reaches the protected resource under a URI
that no rule regexp matches, and the vhost's default rule decides
access. Deny rules, identity and group conditions, and unprotect and
skip rules are bypassed alike.

Only a vhost whose default rule is more permissive than its other rules
is affected. An authenticated user then reaches any URL a locationRules
regexp was meant to restrict, but gains no more than that default rule
already grants.

Problem types
-------------
- CWE-863 Incorrect Authorization
- CWE-180 Incorrect Behavior Order: Validate Before Canonicalize

Solutions
---------
Upgrade to Lemonldap-NG-Handler 2.16.10, 2.21.6 or 2.23.4 or later.
Only 2.23.4 is on CPAN; the 2.16.10 and 2.21.6 LTS releases are
available from https://lemonldap-ng.org/download.html.

References
----------
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3723
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.16.10
https://www.cve.org/CVERecord?id=CVE-2020-24660

Credits
-------
Deepseek agent, Linagora, finder

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




