Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wcq4-9xxp-5px6

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

EPSS

Процентиль: 23%
0.00303
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
redhat
8 дней назад

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

CVSS3: 9.8
nvd
8 дней назад

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

EPSS

Процентиль: 23%
0.00303
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347