User enumeration In ldap-account-manager
Description
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 8.0.1-0+deb11u1 | ||
debian 13 | 8.0.1-1 | ||
debian 12 | 8.0.1-1 |
Aliases
1. 2. 3. 4. 5.