CVE-2023-44469: SSRF
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the requesturi authorization parameter. This is similar to CVE-2020-10770.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-44469.
What is the severity of CVE-2023-44469?
The severity of CVE-2023-44469 is medium.
What software versions are affected by CVE-2023-44469?
LemonLDAP::NG versions up to and excluding 2.17.1 are affected by CVE-2023-44469.
How does CVE-2023-44469 affect the OpenID Connect Issuer in LemonLDAP::NG?
CVE-2023-44469 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter in the OpenID Connect Issuer in LemonLDAP::NG.
Are there any references available for CVE-2023-44469?
Yes, here are some references for CVE-2023-44469: [1] (https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2998), [2] (https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.17.1), [3] (https://security.lauritz-holtmann.de/post/sso-security-ssrf/).