<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Possible nginx LDAP security flaw]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I just came across these two posts:</p>
<ul>
<li><a href="https://github.com/AgainstTheWest/NginxDay" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/AgainstTheWest/NginxDay</a></li>
<li><a href="https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/</a></li>
</ul>
<p dir="auto">Apparently, there is a flaw in the <a href="https://github.com/nginxinc/nginx-ldap-auth" target="_blank" rel="noopener noreferrer nofollow ugc">nginx-ldap-auth</a> module.</p>
<p dir="auto">I know that Cloudron uses nginx a lot, and LDAP as well, so I wanted to make you aware of this.</p>
<p dir="auto">I lack the knowledge to determine whether Cloudron is vulnerable.</p>
<p dir="auto">Could you please investigate and remediate if necessary?</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.cloudron.io/topic/6832/possible-nginx-ldap-security-flaw</link><generator>RSS for Node</generator><lastBuildDate>Mon, 11 May 2026 17:56:52 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/6832.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 16 Apr 2022 16:48:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Possible nginx LDAP security flaw on Sun, 17 Apr 2022 11:50:12 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for the info, but we do not use this module, so we are all good.</p>
]]></description><link>https://forum.cloudron.io/post/46262</link><guid isPermaLink="true">https://forum.cloudron.io/post/46262</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Sun, 17 Apr 2022 11:50:12 GMT</pubDate></item><item><title><![CDATA[Reply to Possible nginx LDAP security flaw on Sat, 16 Apr 2022 22:36:12 GMT]]></title><description><![CDATA[<p dir="auto">pinging <a class="plugin-mentions-group plugin-mentions-a" href="/groups/staff" aria-label="Profile: staff">@<bdi>staff</bdi></a></p>
]]></description><link>https://forum.cloudron.io/post/46254</link><guid isPermaLink="true">https://forum.cloudron.io/post/46254</guid><dc:creator><![CDATA[BrutalBirdie]]></dc:creator><pubDate>Sat, 16 Apr 2022 22:36:12 GMT</pubDate></item></channel></rss>