Vulnerabilities in NGINX's LDAP Reference Implementation
ID: 58f4d111-5140-53b3-a3d0-f5e7d0be68f0
STIX ID: report--58f4d111-5140-53b3-a3d0-f5e7d0be68f0
Feed Name: Arctic Wolf Blog
NGINX published an advisory on three vulnerabilities in its LDAP reference implementation that can enable LDAP injection and authentication bypass when the non-production nginx-ldap-auth daemon is used (conditions include use of ngx_http_auth_request, python-ldap, and specific configuration patterns). NGINX Open Source and NGINX Plus are not affected unless the reference implementation is deployed; BlueHornet claims an experimental PoC and limited successful tests but those claims are unverified. NGINX recommends replacing the reference implementation with a production-grade LDAP integration and auditing deployments that match the specified vulnerable conditions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
