Lack of URL normalization may lead to authorization bypass when URL access rules are used
Moderate severity
GitHub Reviewed
Published
Sep 9, 2020
in
LemonLDAPNG/node-lemonldap-ng-handler
•
Updated Jan 9, 2023
Description
Reviewed
Sep 9, 2020
Published to the GitHub Advisory Database
Sep 9, 2020
Last updated
Jan 9, 2023
Impact
When access rules are used inside a protected host, some URL encodings may bypass filtering system.
Patches
Version 0.5.2 includes a patch that fixes the vulnerability
Workarounds
No way for users to fix or remediate the vulnerability without upgrading
References
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
For more information
If you have any questions or comments about this advisory:
References