28 lines
927 B
JSON
Raw Normal View History

{
"id": "CVE-2023-44469",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-09-29T07:15:14.073",
"lastModified": "2023-09-29T07:15:14.073",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770."
}
],
"metrics": {},
"references": [
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/2998",
"source": "cve@mitre.org"
},
{
"url": "https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.17.1",
"source": "cve@mitre.org"
},
{
"url": "https://security.lauritz-holtmann.de/post/sso-security-ssrf/",
"source": "cve@mitre.org"
}
]
}