Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in LemonLDAP::NG, a system used for identity management and single sign-on. The issue allows unauthenticated attackers to potentially confirm the validity of access tokens and access their metadata, which could lead to the de-anonymization of users across different services. This matters because it weakens user privacy protections and pseudonymity.
- Unauthenticated attackers can inspect access tokens.
- It compromises user privacy and pseudonymous identifiers.
- Verify relevance and assess exposure to user data.
Attack Path
How an attacker could exploit the issue
An attacker who possesses an active access token can bypass authentication checks on the OAuth2 token introspection endpoint. This is possible because the system does not properly verify the client secret for public Relying Parties, allowing an attacker to confirm a token's validity and retrieve its associated metadata. The vulnerability enables an attacker to correlate user identifiers across different Relying Parties, compromising per-client and pseudonymous identification.
- No authentication required.
- Introspection endpoint bypasses secret check.
- User identifier correlation risk.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an unauthenticated attacker could confirm the activity and retrieve metadata of OAuth2 tokens by exploiting a flaw in how client secrets are handled for public Relying Parties. This could allow an attacker to translate user identifiers between different Relying Parties, compromising pseudonymous and per-client identifiers.
- Token metadata and user identifiers.
- Unauthenticated access to token introspection endpoint.
- Defeat per-client and pseudonymous identifiers.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world responsibility for this vulnerability likely lies with the platform or infrastructure teams managing the LemonLDAP::NG deployment, in coordination with security and application owners who rely on its single sign-on (SSO) capabilities. The immediate practical step is to inventory all LemonLDAP::NG instances, determine their reachability and criticality, and identify the specific application or service owners who use them. Once confirmed, a risk-based remediation plan can be developed, prioritizing instances that are externally accessible and handle sensitive user data.
- Platform/Infrastructure teams own the issue.
- Verify LemonLDAP::NG instance reachability and criticality.
- Plan remediation based on exposure and impact.