Netflix lemur是美国Netflix公司开源的一个证书管理工具。 Netflix lemur 1.9.3之前版本存在服务端请求伪造漏洞,该漏洞源于对acme_url验证不足,PUT /api/1/authorities/接口传递选项时未应用ACME_DIRECTORY_HOST_ALLOWLIST检查,持有authority角色的用户可将存储的acme_url替换为内部服务或实例元数据URL,导致服务端请求伪造,可能暴露内部服务或云元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55166 | 9.9 CRITICAL | Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access |
| CVE-2026-48508 | 8.8 HIGH | Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission |
| CVE-2026-71308 | 8.1 HIGH | Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation |
| CVE-2026-71307 | 7.7 HIGH | Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP |
| CVE-2026-70666 | 7.4 HIGH | Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs |
| CVE-2026-71417 | 7.3 HIGH | Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate recor |
| CVE-2026-71317 | 6.5 MEDIUM | Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority |
| CVE-2026-70667 | 6.3 MEDIUM | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects an |
| CVE-2026-55162 | 6.3 MEDIUM | Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and |
| CVE-2026-55163 | 6.3 MEDIUM | Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite |
| CVE-2026-55164 | 4.9 MEDIUM | Lemur: Plaintext password storage in Lemur user-update path |
| CVE-2026-55165 | 4.8 MEDIUM | Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap |
| CVE-2026-71322 | 4.3 MEDIUM | Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requ |
No comments yet