Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28091

Опубликовано: 01 июн. 2021
Источник: redhat
CVSS3: 8.8

Описание

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

An XML Signature Wrapping (XSW) vulnerability was found in Lasso. This flaw allows an attacker to modify a valid SAML response to include an unsigned SAML assertion, which may be used to impersonate another valid user recognized by the service using Lasso. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.

Отчет

Lasso is provided in Red Hat Enterprise Linux 7, and 8 only as a dependency of mod_auth_mellon, without development files. The way mod_auth_mellon uses Lasso makes it not vulnerable to this flaw, because SAML responses are additionally validated to have exactly one assertion, thus it is not possible for an attacker to include an unsigned SAML assertion after a signed valid one. For this reason this flaw has been rated as Moderate on Red Hat Enterprise Linux 8. Red Hat Enterprise Linux 7 also provides a lasso-python package that can be used to create python applications that use Lasso, however Red Hat only ships ipsilon which uses it. Ipsilon does not use the vulnerable functions of Lasso. Considering the presence of lasso-python in Red Hat Enterprise Linux 7, this flaw has been rated as Important there.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6lassoOut of support scope
Red Hat Enterprise Linux 9lassoNot affected
Red Hat Enterprise Linux 7lassoFixedRHSA-2021:298902.08.2021
Red Hat Enterprise Linux 8lassoFixedRHSA-2021:432509.11.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-347->CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1940089lasso: XML signature wrapping vulnerability when parsing SAML responses

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

CVSS3: 7.5
nvd
около 4 лет назад

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 4 лет назад

Lasso all versions prior to 2.7.0 has improper verification of a crypt ...

suse-cvrf
почти 4 года назад

Security update for lasso

8.8 High

CVSS3