Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-249c-5cfq-cwqh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

EPSS

Процентиль: 52%
0.00292
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-347

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.

EPSS

Процентиль: 52%
0.00292
Низкий

8.8 High

CVSS3

Дефекты

CWE-269
CWE-347