Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29108

Опубликовано: 01 окт. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:esri:portal_for_arcgis:*:*:*:*:*:*:*:*
Версия до 10.9 (включая)

EPSS

Процентиль: 52%
0.00292
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-347
CWE-347

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

EPSS

Процентиль: 52%
0.00292
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-347
CWE-347