CVE-2022-31087
Summary
| CVE | CVE-2022-31087 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-27 21:15:00 UTC |
| Updated | 2023-07-24 13:17:00 UTC |
| Description | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An attacker capable of writing files under www-data privileges can write a web-shell into this directory, and gain a Code Execution on the host. This issue has been fixed in version 8.0. Users unable to upgrade should disallow executing PHP scripts in (/var/lib/ldap-account-manager/)tmp directory. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Incorrect Default Permissions · Advisory · LDAPAccountManager/lam · GitHub |
CONFIRM |
github.com |
|
| Debian -- Security Information -- DSA-5177-1 ldap-account-manager |
DEBIAN |
www.debian.org |
|
| Merge pull request from GHSA-r387-grjx-qgvw · LDAPAccountManager/lam@f1d5d04 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180808 Debian Security Update for ldap-account-manager (DSA 5177-1)
- 183130 Debian Security Update for ldap-account-manager (CVE-2022-31087)