Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restri…
中危 CVSS 6.5
摘要
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's locationRules regular expressions against REQUEST_URI, the raw request line, while the web server routes on the path it has already percent-decoded and normalized. A request that percent-encodes a character of the path, inserts dot segments, or doubles a slas…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3723
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.16.10
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4
- https://www.cve.org/CVERecord?id=CVE-2020-24660
- https://lists.debian.org/debian-lts-announce/2026/09/msg00032.html
- https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3723
时间线
- nvd_ingest NVD