Palo Alto Networks · Cortex Xsoar · CVE-2021-3034
**Name of the Vulnerable Software and Affected Versions**
Cortex XSOAR versions 5.5.0 through 5.5.0 build 98621
Cortex XSOAR versions 6.0.1 through 6.0.1 build 830028
Cortex XSOAR versions 6.0.2 through 6.0.2 build 98622
Cortex XSOAR versions 6.1.0 through 6.1.0 build 848143
**Description**
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration.
**Recommendations**
For Cortex XSOAR version 5.5.0, update to a build later than 98621 to resolve the issue.
For Cortex XSOAR version 6.0.1, update to a build later than 830029 to resolve the issue.
For Cortex XSOAR version 6.0.2, update to a build later than 98623 to resolve the issue.
For Cortex XSOAR version 6.1.0, update to a build later than 848144 to resolve the issue.
As a temporary workaround, consider restricting access to the '/var/log/demisto/' server logs to minimize the risk of exploitation.