Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31261

Опубликовано: 24 мая 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 4.3
EPSS Низкий

Описание

An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A remote attacker can send a request crafted with an XXE payload to invoke a malicious DTD hosted on a system that they control. This results in reading local files that the application has access to.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:morpheusdata:morpheus:*:*:*:*:*:*:*:*
Версия до 5.2.16 (включая)
cpe:2.3:a:morpheusdata:morpheus:*:*:*:*:*:*:*:*
Версия от 5.4.0 (включая) до 5.4.4 (включая)

EPSS

Процентиль: 57%
0.00357
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A remote attacker can send a request crafted with an XXE payload to invoke a malicious DTD hosted on a system that they control. This results in reading local files that the application has access to.

EPSS

Процентиль: 57%
0.00357
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-611