Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

redhat Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2020-27846

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 17 Π΄Π΅ΠΊ. 2020
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: redhat
CVSS3: 9.8

ОписаниС

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

ΠžΡ‚Ρ‡Π΅Ρ‚

Grafana in the OpenShift Container Platform (OCP) and OpenShift ServiceMesh) uses oauth-proxy as an Auth Proxy, and therefore does not make use of the vulnerable SAML Authentication in the github.com/crewjam/saml module used by Grafana. Additionally, SAML is only available in the enterprise version of grafana, but as the code is still packaged, it has been marked Low impact. Red Hat Gluster Storage 3, Red Hat Ceph Storage 2, 3 and 4 ships old versions of grafana where β€˜crewjam/saml’ module is not included. Therefore these products are not affected by this vulnerability. grafana as shipped with Red Hat Enterprise Linux 8 packages a vulnerable version of crewjam/saml but does not use it, as SAML is only available for the Enterprise version of grafana. For this reason, this flaw has been marked Low impact.

Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΠ°ΠΊΠ΅Ρ‚Ρ‹

ΠŸΠ»Π°Ρ‚Ρ„ΠΎΡ€ΠΌΠ°ΠŸΠ°ΠΊΠ΅Ρ‚Π‘ΠΎΡΡ‚ΠΎΡΠ½ΠΈΠ΅Π Π΅ΠΊΠΎΠΌΠ΅Π½Π΄Π°Ρ†ΠΈΡΠ Π΅Π»ΠΈΠ·
OpenShift Service Mesh 1servicemesh-grafanaOut of support scope
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
Red Hat 3scale API Management Platform 23scale-operator-containerNot affected
Red Hat Ceph Storage 2grafanaNot affected
Red Hat Ceph Storage 3grafanaNot affected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Not affected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat OpenShift Container Platform 3.11openshift3/grafanaFix deferred
Red Hat Storage 3grafanaNot affected
Red Hat Enterprise Linux 8grafanaFixedRHSA-2021:185918.05.2021

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Π”ΠΎΠΏΠΎΠ»Π½ΠΈΡ‚Π΅Π»ΡŒΠ½Π°Ρ информация

Бтатус:

Critical
Π”Π΅Ρ„Π΅ΠΊΡ‚:
CWE-115
https://bugzilla.redhat.com/show_bug.cgi?id=1907670crewjam/saml: authentication bypass in saml authentication

9.8 Critical

CVSS3

БвязанныС уязвимости

CVSS3: 9.8
nvd
большС 5 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS3: 9.8
github
ΠΎΠΊΠΎΠ»ΠΎ 5 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

XML Processing error in github.com/crewjam/saml

rocky
ΠΎΠΊΠΎΠ»ΠΎ 5 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

Moderate: grafana security, bug fix, and enhancement update

oracle-oval
ΠΎΠΊΠΎΠ»ΠΎ 5 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

ELSA-2021-1859: grafana security, bug fix, and enhancement update (MODERATE)

9.8 Critical

CVSS3

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2020-27846