Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg0NHgtcjg0dy04djY3
Lack of URL normalization may lead to authorization bypass when URL access rules are used
Impact
When access rules are used inside a protected host, some URL encodings may bypass filtering system.
Patches
Version 0.5.2 includes a patch that fixes the vulnerability
Workarounds
No way for users to fix or remediate the vulnerability without upgrading
References
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
For more information
If you have any questions or comments about this advisory:
- Open an issue in this repository or LemonLDAP::NG GitLab
- Email us at [email protected]
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXg0NHgtcjg0dy04djY3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 4 years ago
Updated: almost 2 years ago
CVSS Score: 6.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-x44x-r84w-8v67, CVE-2020-24660
References:
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/security/advisories/GHSA-x44x-r84w-8v67
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/commit/136aa83ed431462fa42ce17b7f9b24e056de06be
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
- https://www.npmjs.com/package/lemonldap-ng-handler
- https://nvd.nist.gov/vuln/detail/CVE-2020-24660
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/releases/tag/0.5.2
- https://www.debian.org/security/2020/dsa-4762
- https://snyk.io/vuln/SNYK-JS-NODELEMONLDAPNGHANDLER-655999
- https://github.com/advisories/GHSA-x44x-r84w-8v67
Blast Radius: 2.0
Affected Packages
npm:lemonldap-ng-handler
Dependent packages: 2Dependent repositories: 2
Downloads: 10 last month
Affected Version Ranges: < 0.5.2
Fixed in: 0.5.2
All affected versions: 0.4.0, 0.5.0, 0.5.1
All unaffected versions: 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4