LemonLDAP-NG LemonLDAP::NG Handler 0.2.9 for Node.js

CPE Details

LemonLDAP-NG LemonLDAP::NG Handler 0.2.9 for Node.js
0.2.9
2020-09-14
12h57 +00:00
2021-03-04
15h01 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng_handler:0.2.9:*:*:*:*:node.js:*:*

Informations

Vendor

lemonldap-ng

Product

lemonldap::ng_handler

Version

0.2.9

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-24660 2020-09-14 10h51 +00:00 An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
9.8
Critical