9.8
CVE-2019-19791
- EPSS 0.78%
- Veröffentlicht 29.05.2023 19:15:09
- Zuletzt bearbeitet 14.01.2025 18:15:20
- Erkennungen
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lemonldap-ng ≫ Lemonldap::ng Version < 2.0.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.511 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/issues/1943
https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-0-7-is-out