PT-2023-11344 · Apache · Apache Http Server
Clément Oudot
+1
·
Published
2023-05-29
·
Updated
2025-01-14
·
CVE-2019-19791
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LemonLDAP::NG versions prior to 2.0.7
Description
The default Apache HTTP Server configuration in LemonLDAP::NG does not properly restrict access to SOAP/REST endpoints when certain setup options are used. This allows an attacker to bypass a Require directive by inserting index.fcgi/index.fcgi into a URL.
Recommendations
For versions prior to 2.0.7, update to version 2.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the SOAP/REST endpoints to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server