CVE-2023-44469
29.09.2023, 07:15
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.
Vendor | Product | Version |
---|---|---|
lemonldap-ng | lemonldap\ | 𝑥 < 2.17.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References