PT-2020-16398 · Google+2 · Go+2

Published

2020-12-17

·

Updated

2022-02-11

·

CVE-2020-26276

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 3.5.1
Description The issue arises from problems in Go's standard library XML parsing, allowing an attacker to mutate a valid SAML response and modify the trusted document. This can result in allowing unverified logins from a SAML IdP. Users that configure Fleet with SSO login may be vulnerable to this issue.
Recommendations For versions prior to 3.5.1, upgrade to version 3.5.1 to resolve the issue. If upgrade to 3.5.1 is not possible, disable SSO authentication in Fleet as a temporary workaround.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1107
CVE-2020-26276
GHSA-W3WF-CFX3-6GCX

Affected Products

Alt Linux
Fleet
Go