CVE 8 HIGH

CVE-2025-59518_CVE-2025-59518

8 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

Basic Information

ID CVE-2025-59518
Source mitre
Published Sep 17, 2025 at 00:00
Modified Sep 17, 2025 at 03:16

Affected Product

Vendor lemonldap-ng
Product LemonLDAP::NG
Affected Versions lemonldap-ng LemonLDAP::NG 0
lemonldap-ng LemonLDAP::NG 2.17.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.