CVE-2020-24660: Debian Linux
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemonldap::NG handler for Node.js" package.
Affected products
- Debian Debian Linux: version 10.0 only
- Lemonldap-NG Lemonldap::ng: up to and including 2.0.8
- Lemonldap-NG Lemonldap::ng Handler: up to and including 0.5.2
Published 2020-09-14. Last modified 2026-06-17.