Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LemonLDAP::NG 默认配置问题漏洞
Vulnerability Description
LemonLDAP::NG是一套Web单点登录和访问管理软件。 LemonLDAP::NG 2.0.2 + ds-7 + deb10u5 之前版本存在默认配置问题漏洞。该漏洞源于网络系统或产品使用了不安全的默认配置。攻击者可以利用该漏洞绕过授权。
CVSS Information
N/A
Vulnerability Type
N/A