Описание
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
lasso | fixed | 2.6.1-3 | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=1940089
https://blogs.akamai.com/2021/06/saml-implementation-vulnerability-impacting-some-akamai-services.html
https://blogs.akamai.com/2021/06/akamai-eaa-impersonation-vulnerability---a-deep-dive.html
https://git.entrouvert.org/lasso.git/commit/?id=ea7e5efe9741e1b1787a58af16cb15b40c23be5a
EPSS
Процентиль: 73%
0.00772
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 4 лет назад
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
CVSS3: 8.8
redhat
около 4 лет назад
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
CVSS3: 7.5
nvd
около 4 лет назад
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
EPSS
Процентиль: 73%
0.00772
Низкий