CVE-2020-24660
published 2020-09-14CVE-2020-24660: An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.34%
81.8th percentile
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | lemonldap-ng | < lemonldap-ng 2.0.9+ds-1 (bookworm) | lemonldap-ng 2.0.9+ds-1 (bookworm) |
| lemonldap-ng | lemonldap | <= 2.0.8 | — |
| lemonldap-ng | lemonldap | <= 0.5.2 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-24660: lemonldap-ng - An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An a...
vendor_debian·2020·CVSS 9.8
CVE-2020-24660 [CRITICAL] CVE-2020-24660: lemonldap-ng - An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An a...
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Scope: local
bookworm: resolved (fixed in 2.0.9+ds-1)
bullseye: resolved (fixed in 2.0.9+ds-1)
forky: resolved (fixed in 2.0.9+ds-1)
sid: resolved (fixed in 2.0.9+ds-1)
trixie: resolved (fixed in 2.0.9+ds-1)
OSV
CVE-2020-24660: An issue was discovered in LemonLDAP::NG through 2
osv·2020-09-14·CVSS 9.8
CVE-2020-24660 [CRITICAL] CVE-2020-24660: An issue was discovered in LemonLDAP::NG through 2
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
GHSA
Lack of URL normalization may lead to authorization bypass when URL access rules are used
ghsa·2020-09-09
CVE-2020-24660 [MEDIUM] CWE-287 Lack of URL normalization may lead to authorization bypass when URL access rules are used
Lack of URL normalization may lead to authorization bypass when URL access rules are used
### Impact
When access rules are used inside a protected host, some URL encodings may bypass filtering system.
### Patches
Version 0.5.2 includes a patch that fixes the vulnerability
### Workarounds
No way for users to fix or remediate the vulnerability without upgrading
### References
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [this repository](https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/issues) or [LemonLDAP::NG GitLab](https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues)
* Email us at [[email protected]](mailto:[email protected])
OSV
Lack of URL normalization may lead to authorization bypass when URL access rules are used
osv·2020-09-09
CVE-2020-24660 [MEDIUM] Lack of URL normalization may lead to authorization bypass when URL access rules are used
Lack of URL normalization may lead to authorization bypass when URL access rules are used
### Impact
When access rules are used inside a protected host, some URL encodings may bypass filtering system.
### Patches
Version 0.5.2 includes a patch that fixes the vulnerability
### Workarounds
No way for users to fix or remediate the vulnerability without upgrading
### References
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [this repository](https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/issues) or [LemonLDAP::NG GitLab](https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues)
* Email us at [[email protected]](mailto:[email protected])
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/releases/tag/0.5.2https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/security/advisories/GHSA-x44x-r84w-8v67https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290https://www.debian.org/security/2020/dsa-4762https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/releases/tag/0.5.2https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/security/advisories/GHSA-x44x-r84w-8v67https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290https://www.debian.org/security/2020/dsa-4762
2020-09-14
Published