Skip to content

Lack of URL normalization may lead to authorization bypass when URL access rules are used

High
guimard published GHSA-x44x-r84w-8v67 Sep 9, 2020

Package

npm lemonldap-ng-handler (npm)

Affected versions

< 0.5.1

Patched versions

0.5.2

Description

Impact

When access rules are used inside a protected host, some URL encodings may bypass filtering system.

Patches

Version 0.5.2 includes a patch that fixes the vulnerability

Workarounds

No way for users to fix or remediate the vulnerability without upgrading

References

https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2020-24660

Weaknesses

No CWEs