Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-47151

Опубликовано: 05 нояб. 2025
Источник: redhat
CVSS3: 9.8

Описание

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.8.2 and prior. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6lassoOut of support scope
Red Hat Enterprise Linux 7 Extended Lifecycle SupportlassoFixedRHSA-2025:2140417.11.2025
Red Hat Enterprise Linux 8lassoFixedRHSA-2025:2162817.11.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupportlassoFixedRHSA-2025:2139917.11.2025
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlassoFixedRHSA-2025:2140217.11.2025
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlassoFixedRHSA-2025:2140217.11.2025
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlassoFixedRHSA-2025:2140117.11.2025
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicelassoFixedRHSA-2025:2140117.11.2025
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionslassoFixedRHSA-2025:2140117.11.2025
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicelassoFixedRHSA-2025:2140017.11.2025

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2412739lasso: Type confusion in Entr'ouvert Lasso

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.

CVSS3: 9.8
nvd
5 месяцев назад

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.

CVSS3: 9.8
debian
5 месяцев назад

A type confusion vulnerability exists in the lasso_node_impl_init_from ...

rocky
5 месяцев назад

Critical: lasso security update

rocky
5 месяцев назад

Critical: lasso security update

9.8 Critical

CVSS3