First published: Mon Jun 27 2022(Updated: )
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the /config/templates/pdf/ directory is accessible for remote users. This is not a default configuration of LAM. This issue has been fixed in version 8.0. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ldap-account-manager | 8.0.1-0+deb11u1 8.3-1 | |
LDAP Account Manager | <8.0 | |
Debian Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31086 is considered a critical vulnerability that allows for remote code execution due to improper regular expression validations.
To fix CVE-2022-31086, upgrade to LDAP Account Manager version 8.0.1-0+deb11u1 or 8.3-1.
CVE-2022-31086 affects LDAP Account Manager versions prior to 8.0.
CVE-2022-31086 primarily affects installations of LDAP Account Manager on Debian Linux systems.
Yes, CVE-2022-31086 can lead to remote code execution, potentially allowing attackers to breach sensitive data.