PT-2018-16216 · Elastic · X-Pack Security

CVE-2018-3822

·

Publicado

2018-03-30

·

Atualizado

2023-03-24

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions X-Pack Security versions 6.2.0 through 6.2.2
Description The issue allows for a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might impersonate a legitimate user if the SAML Identity Provider allows self registration with arbitrary identifiers and the attacker can register an account with an identifier that shares a suffix with a legitimate account. Both conditions must be true to exploit this flaw.
Recommendations For versions 6.2.0 through 6.2.2, consider restricting the SAML Identity Provider to prevent self registration with arbitrary identifiers as a temporary workaround until a patch is available.

Correção

Improper Authentication

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3822

Produtos afetados

X-Pack Security