An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2367-1 lemonldap-ng security update
Debian DSA Debian DSA DSA-4762-1 lemonldap-ng security update
EUVD EUVD EUVD-2020-1371 An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Github GHSA Github GHSA GHSA-x44x-r84w-8v67 Lack of URL normalization may lead to authorization bypass when URL access rules are used
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:19:09.076Z

Reserved: 2020-08-26T00:00:00

Link: CVE-2020-24660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-14T13:15:10.030

Modified: 2024-11-21T05:15:27.350

Link: CVE-2020-24660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.