PT-2019-10284 · Zendesk · Zendesk Samlr

Watikri

·

Publicado

2019-07-26

·

Atualizado

2019-08-01

·

CVE-2018-20857

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Zendesk Samlr versions prior to 2.6.2
Description: The issue allows an XML nodes comment attack, where an attacker can manipulate the name id node by including a comment (<!---->) followed by the attacker's domain name, potentially allowing for malicious activities. This can be initiated by setting up a name id node with an email address, such as user@example.com, followed by the comment and the attacker's domain.
Recommendations: For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of XML nodes comments in the name id node to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20857
GHSA-QPXP-5J56-GG3X

Produtos afetados

Zendesk Samlr