Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stefan Lubienetzki

#48570of 53,633
5.1Total CVSS
Vulnerabilities · 1
PT-2021-18715
5.1
2021-03-10
Palo Alto Networks · Cortex Xsoar · CVE-2021-3034
**Name of the Vulnerable Software and Affected Versions** Cortex XSOAR versions 5.5.0 through 5.5.0 build 98621 Cortex XSOAR versions 6.0.1 through 6.0.1 build 830028 Cortex XSOAR versions 6.0.2 through 6.0.2 build 98622 Cortex XSOAR versions 6.1.0 through 6.1.0 build 848143 **Description** An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration. **Recommendations** For Cortex XSOAR version 5.5.0, update to a build later than 98621 to resolve the issue. For Cortex XSOAR version 6.0.1, update to a build later than 830029 to resolve the issue. For Cortex XSOAR version 6.0.2, update to a build later than 98623 to resolve the issue. For Cortex XSOAR version 6.1.0, update to a build later than 848144 to resolve the issue. As a temporary workaround, consider restricting access to the '/var/log/demisto/' server logs to minimize the risk of exploitation.