GHSA-x44x-r84w-8v67
Lack of URL normalization may lead to authorization bypass when URL access rules are used
Quick fix
GHSA-x44x-r84w-8v67 — lemonldap-ng-handler: upgrade to the fixed version with the command below.
npm install lemonldap-ng-handler@0.5.2Details
### Impact When access rules are used inside a protected host, some URL encodings may bypass filtering system.
### Patches Version 0.5.2 includes a patch that fixes the vulnerability
### Workarounds No way for users to fix or remediate the vulnerability without upgrading
### References https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290
### For more information If you have any questions or comments about this advisory: * Open an issue in [this repository](https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/issues) or [LemonLDAP::NG GitLab](https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues) * Email us at [lemonldap-ng-users@ow2.org](mailto:lemonldap-ng-users@ow2.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/security/advisories/GHSA-x44x-r84w-8v67[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-24660[ADVISORY]
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/commit/136aa83ed431462fa42ce17b7f9b24e056de06be[WEB]
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler[PACKAGE]
- https://github.com/LemonLDAPNG/node-lemonldap-ng-handler/releases/tag/0.5.2[WEB]
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2290[WEB]
- https://snyk.io/vuln/SNYK-JS-NODELEMONLDAPNGHANDLER-655999[WEB]
- https://www.debian.org/security/2020/dsa-4762[WEB]
- https://www.npmjs.com/package/lemonldap-ng-handler[WEB]