Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2020-27846 - CERT CVE
CVE-2020-27846
ID
CVE-2020-27846
Sažetak
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Reference
https://github.com/crewjam/saml/security/advisories/GHSA-4hq8-gmxx-h6w9
https://bugzilla.redhat.com/show_bug.cgi?id=1907670
https://grafana.com/blog/2020/12/17/grafana-6.7.5-7.2.3-and-7.3.6-released-with-important-security-fix-for-grafana-enterprise/
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/
https://security.netapp.com/advisory/ntap-20210205-0002/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YUTKIRWT6TWU7DS6GF3EOANVQBFQZYI/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICP3YRY2VUCNCF2VFUSK77ZMRIC77FEM/
CVSS
Base:
10.0
Impact:
10.0
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
COMPLETE
COMPLETE
COMPLETE
CVSS vektor
AV:N/AC:L/Au:N/C:C/I:C/A:C
Zadnje važnije ažuriranje
07-11-2023 - 03:21
Objavljeno
21-12-2020 - 16:15