Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-44469

Опубликовано: 29 сент. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lemonldap-ng:lemonldap\:\:ng:*:*:*:*:*:*:*:*
Версия до 2.17.1 (исключая)

EPSS

Процентиль: 63%
0.00436
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

CVSS3: 4.3
debian
больше 2 лет назад

A Server-Side Request Forgery issue in the OpenID Connect Issuer in Le ...

CVSS3: 4.3
github
больше 2 лет назад

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

EPSS

Процентиль: 63%
0.00436
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918