Логотип exploitDog
bind:CVE-2021-29108
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-29108

Количество 2

Количество 2

nvd логотип

CVE-2021-29108

около 4 лет назад

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-249c-5cfq-cwqh

больше 3 лет назад

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-29108

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-249c-5cfq-cwqh

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker to impersonate another account.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу