PT-2020-6774 · Unknown · Lemonldap::Ng+1
Maxime Besson
·
Published
2020-08-20
·
Updated
2020-09-18
·
CVE-2020-24660
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LemonLDAP::NG versions through 2.0.8
Lemonldap::NG handler for Node.js versions before 0.5.2
Description
An issue in LemonLDAP::NG allows an attacker to bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This is related to errors in security mechanisms, which can allow a remote attacker to gain unauthorized access to information. When access rules are used inside a protected host, some URL encodings may bypass the filtering system.
Recommendations
For LemonLDAP::NG versions through 2.0.8, update to a version that includes the patch for this issue.
For Lemonldap::NG handler for Node.js versions before 0.5.2, update to version 0.5.2 or later, which includes a patch that fixes the vulnerability.
As a temporary workaround, consider restricting access to protected Virtual Hosts until a patch is applied.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lemonldap::Ng
Lemonldap::Ng Handler For Node.Js