Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LemonLDAP::NG 安全漏洞
Vulnerability Description
LemonLDAP::NG是一套Web单点登录和访问管理软件。 LemonLDAP::NG(lemonldap-ng)存在安全漏洞,该漏洞源于认的 Apache HTTP 服务器配置没有正确限制对 SOAP/REST 端点的访问,攻击者利用该漏洞可以将 index.fcgi/index.fcgi 插入 URL 以绕过 Require 指令。
CVSS Information
N/A
Vulnerability Type
N/A