VulnerabilityModified
CVE-2022-31088
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory.
MEDIUM 5.3EPSS 1.24%
Does this matter?
Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.
Description
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.24% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- ldap-account-manager/ldap account manager · debian/debian linux
- Source
- security-advisories@github.com
References
- https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4Patch, Third Party Advisory
- https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-wxf8-9x99-6gp4Third Party Advisory
- https://www.debian.org/security/2022/dsa-5177Third Party Advisory
- https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4Patch, Third Party Advisory
- https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-wxf8-9x99-6gp4Third Party Advisory
- https://www.debian.org/security/2022/dsa-5177Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.