Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxqv-qm7m-363x

Опубликовано: 17 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

EPSS

Процентиль: 41%
0.00195
Низкий

8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8
ubuntu
5 месяцев назад

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

CVSS3: 8
redhat
5 месяцев назад

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

CVSS3: 8
nvd
5 месяцев назад

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ during rule evaluation. Thus, an administrator who can edit a rule evaluated by the Safe jail can execute commands on the server.

CVSS3: 8
debian
5 месяцев назад

In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS ...

EPSS

Процентиль: 41%
0.00195
Низкий

8 High

CVSS3

Дефекты

CWE-78