CVE-2020-24660: Critical severity lemonldap::ng vulnerability
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24660?
CVE-2020-24660 has been rated as moderate severity due to the potential bypass of access control for protected resources.
How can I fix CVE-2020-24660?
To mitigate CVE-2020-24660, upgrade LemonLDAP::NG to version 2.0.9 or later, or make sure to use the appropriate patch.
Which versions of LemonLDAP::NG are affected by CVE-2020-24660?
CVE-2020-24660 affects LemonLDAP::NG versions 2.0.8 and earlier.
Does CVE-2020-24660 affect Node.js applications using LemonLDAP::NG?
Yes, versions of the 'Lemonldap::NG handler for Node.js' before 0.5.2 are also affected by CVE-2020-24660.
What are the potential consequences of exploiting CVE-2020-24660?
An attacker exploiting CVE-2020-24660 can gain unauthorized access to protected Virtual Hosts by bypassing URL-based access controls.