{"id":"CVE-2012-6426","details":"LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.","modified":"2026-04-10T03:42:34.080561Z","published":"2013-01-01T15:55:02Z","references":[{"type":"FIX","url":"http://jira.ow2.org/browse/LEMONLDAP-570"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/12/19/6"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/12/20/6"}],"schema_version":"1.7.5"}