CVE-2020-24660: Debian Linux

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Lemonldap-NG Lemonldap::ng: up to and including 2.0.8
  • Lemonldap-NG Lemonldap::ng Handler: up to and including 0.5.2

Published 2020-09-14. Last modified 2026-06-17.