Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LemonLDAP::NG SAML XML 签名封装安全漏洞
Vulnerability Description
Lemonldap::NG是模块化的单点登录解决方案,可管理认证和授权。 LemonLDAP::NG 1.2.3之前版本中存在包含XML签名封装的安全漏洞,该漏洞源于不安全使用Lasso库,即使在强制签名检查的情况下,应用程序也没有对SAML签名进行检查。允许攻击者发送包含任意内容的消息通过应用验证,进行进一步攻击。
CVSS Information
N/A
Vulnerability Type
N/A