CVE-2023-44469 | LemonLDAP::NG up to 2.17.0 OpenID Connect Issuer request_uri server-side request forgery (Issue 2998 / EUVD-2023-48806)
A vulnerability described as critical has been identified in LemonLDAP::NG up to 2.17.0. The impacted element is an unknown function of the component OpenID Connect Issuer. Such manipulation of the argument request_uri leads to server-side request forgery.
This vulnerability is documented as CVE-2023-44469. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.