CVE-2022-31087
Incorrect Default Permissions in ldap-account-manager
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An attacker capable of writing files under www-data privileges can write a web-shell into this directory, and gain a Code Execution on the host. This issue has been fixed in version 8.0. Users unable to upgrade should disallow executing PHP scripts in (/var/lib/ldap-account-manager/)tmp directory.
LDAP Account Manager (LAM) es un frontend web para administrar las entradas (por ejemplo, usuarios, grupos, configuraciones DHCP) almacenadas en un directorio LDAP. En versiones anteriores a 8.0, el directorio tmp, al que se accede mediante /lam/tmp/, permite interpretar los archivos .php (y .php5/.php4/.phpt/etc). Un atacante capaz de escribir archivos bajo los privilegios de www-data puede escribir un web-shell en este directorio, y obtener una Ejecución de Código en el host. Este problema ha sido corregido en versión 8.0. Los usuarios que no puedan actualizarse deben deshabilitar la ejecución de scripts PHP en el directorio (/var/lib/ldap-account-manager/)tmp
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-06-27 CVE Published
- 2024-02-16 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-863: Incorrect Authorization
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-q8g5-45m4-q95p | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4 | 2023-07-24 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2022/dsa-5177 | 2023-07-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ldap-account-manager Search vendor "Ldap-account-manager" | Ldap Account Manager Search vendor "Ldap-account-manager" for product "Ldap Account Manager" | < 8.0 Search vendor "Ldap-account-manager" for product "Ldap Account Manager" and version " < 8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|