Candidate: CVE-2019-13031 PublicDate: 2019-06-28 23:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13031 https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1820 Description: LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931117 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_lemonldap-ng: upstream_lemonldap-ng: released (2.0.0+ds-1) precise/esm_lemonldap-ng: DNE trusty_lemonldap-ng: ignored (out of standard support) trusty/esm_lemonldap-ng: DNE xenial_lemonldap-ng: ignored (end of standard support, was needed) bionic_lemonldap-ng: needed cosmic_lemonldap-ng: ignored (reached end-of-life) disco_lemonldap-ng: not-affected (2.0.2+ds-6) eoan_lemonldap-ng: not-affected (2.0.2+ds-6) focal_lemonldap-ng: not-affected (2.0.2+ds-6) groovy_lemonldap-ng: not-affected (2.0.2+ds-6) hirsute_lemonldap-ng: not-affected (2.0.2+ds-6) impish_lemonldap-ng: not-affected (2.0.2+ds-6) jammy_lemonldap-ng: not-affected (2.0.2+ds-6) devel_lemonldap-ng: not-affected (2.0.2+ds-6)