Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Clement_Oudot

#15030de 53,635
17.9CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2023-11344
9.8
2023-05-29
Apache · Apache Http Server · CVE-2019-19791
**Name of the Vulnerable Software and Affected Versions** LemonLDAP::NG versions prior to 2.0.7 **Description** The default Apache HTTP Server configuration in LemonLDAP::NG does not properly restrict access to SOAP/REST endpoints when certain setup options are used. This allows an attacker to bypass a Require directive by inserting index.fcgi/index.fcgi into a URL. **Recommendations** For versions prior to 2.0.7, update to version 2.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP/REST endpoints to minimize the risk of exploitation.
PT-2019-13089
8.1
2019-06-28
Lemonldap · Lemonldap::Ng · CVE-2019-13031
**Name of the Vulnerable Software and Affected Versions** LemonLDAP::NG versions prior to 1.9.20 **Description** The issue is related to an XML External Entity (XXE) problem that occurs when submitting a notification to the notification server. It's worth noting that the notification server is not enabled by default and has a "deny all" rule, which may limit the exposure to this issue. **Recommendations** For versions prior to 1.9.20, update to version 1.9.20 or later to resolve the issue.