Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13415

Опубликовано: 22 мая 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:aviatrix:controller:*:*:*:*:*:*:*:*
Версия до 5.1 (включая)

EPSS

Процентиль: 33%
0.00132
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.

EPSS

Процентиль: 33%
0.00132
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347