Releases: LemonLDAPNG/node-lemonldap-ng-handler
Releases · LemonLDAPNG/node-lemonldap-ng-handler
Replace nodedbi by knex for SQL access
Fix lack of URL normalization
This release fixes CVE-2020-24660. Before this release, when access rules are used inside a protected host, some URL encodings may bypass filtering system (see also security advisory).
0.5.0
BREAKING CHANGE: Cryptographic functions are now compatible with LemonLDAP::NG ≥ 2.0.5 but then are incompatible with previous versions.