Netflix lemur是美国Netflix公司开源的一个证书管理工具。 Netflix Lemur 1.9.3之前版本存在服务端请求伪造漏洞,该漏洞源于对acme_url的更新未经过重新验证,且客户端未验证ACME响应URL的主机是否与配置的目录主机匹配,导致容易受到服务端请求伪造攻击,攻击者可能利用JWS签名请求访问内部服务或云元数据端点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55166 | 9.9 CRITICAL | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access |
| CVE-2026-48508 | 8.8 HIGH | Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission |
| CVE-2026-71308 | 8.1 HIGH | Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation |
| CVE-2026-71307 | 7.7 HIGH | Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP |
| CVE-2026-71303 | 7.7 HIGH | Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admi |
| CVE-2026-71417 | 7.3 HIGH | Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate recor |
| CVE-2026-71317 | 6.5 MEDIUM | Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority |
| CVE-2026-70667 | 6.3 MEDIUM | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects an |
| CVE-2026-55162 | 6.3 MEDIUM | Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and |
| CVE-2026-55163 | 6.3 MEDIUM | Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite |
| CVE-2026-55164 | 4.9 MEDIUM | Lemur: Plaintext password storage in Lemur user-update path |
| CVE-2026-55165 | 4.8 MEDIUM | Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap |
| CVE-2026-71322 | 4.3 MEDIUM | Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requ |
No comments yet