Описание
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.5.4 (исключая)
cpe:2.3:a:fusionauth:saml_v2:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00276
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-611
Связанные уязвимости
github
больше 3 лет назад
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
EPSS
Процентиль: 51%
0.00276
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-611