CVE-2023-44469

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*

History

08 Oct 2023, 19:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/10/msg00014.html -

03 Oct 2023, 17:09

Type Values Removed Values Added
CPE cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*
CWE CWE-918
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Lemonldap-ng
Lemonldap-ng lemonldap\
References (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.17.1 - (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.17.1 - Issue Tracking, Release Notes
References (MISC) https://security.lauritz-holtmann.de/post/sso-security-ssrf/ - (MISC) https://security.lauritz-holtmann.de/post/sso-security-ssrf/ - Not Applicable
References (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2998 - (MISC) https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2998 - Issue Tracking, Patch, Vendor Advisory

29 Sep 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-29 07:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-44469

Mitre link : CVE-2023-44469

CVE.ORG link : CVE-2023-44469


JSON object : View

Products Affected

lemonldap-ng

  • lemonldap\
CWE
CWE-918

Server-Side Request Forgery (SSRF)