Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-249p-r5w7-w969

Опубликовано: 03 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.7

Описание

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

EPSS

Процентиль: 7%
0.00176
Низкий

8.8 High

CVSS4

8.7 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 8.7
nvd
6 дней назад

A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific SSO configurations.

EPSS

Процентиль: 7%
0.00176
Низкий

8.8 High

CVSS4

8.7 High

CVSS3

Дефекты

CWE-347