QID 980547

QID 980547: Nodejs (npm) Security Update for lemonldap-ng-handler (GHSA-x44x-r84w-8v67)

Security update has been released for lemonldap-ng-handler to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

When access rules are used inside a protected host, some URL encodings may bypass filtering system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Version 0.5.2 includes a patch that fixes the vulnerabilityWorkaround:
    No way for users to fix or remediate the vulnerability without upgrading
    Vendor References

    CVEs related to QID 980547

    Software Advisories
    Advisory ID Software Component Link
    GHSA-x44x-r84w-8v67 lemonldap-ng-handler URL Logo github.com/advisories/GHSA-x44x-r84w-8v67