CVE-2020-36659 is a critical vulnerability in Apache::Session::Browseable versions prior to 1.3.6, affecting products like Debian Apache and LemonLDAP::NG. It stems from the default configuration of Net::LDAPS, which fails to validate X.509 certificates when connecting to remote LDAP backends. This allows for a high-impact attack with a CVSS score of 8.1, enabling remote attackers to potentially compromise confidentiality, integrity, and availability without user interaction. Despite its severity, there is currently no public exploit code, Metasploit modules, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.6CPE matchmatch criteria | cpe:2.3:a:lemonldap-ng:apache\:\:session\:\:browsable:*:*:*:*:*:perl:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.