PT-2021-18715 · Palo Alto Networks · Cortex Xsoar
Martin Spielmann
+1
·
Published
2021-03-10
·
Updated
2021-03-24
·
CVE-2021-3034
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cortex XSOAR versions 5.5.0 through 5.5.0 build 98621
Cortex XSOAR versions 6.0.1 through 6.0.1 build 830028
Cortex XSOAR versions 6.0.2 through 6.0.2 build 98622
Cortex XSOAR versions 6.1.0 through 6.1.0 build 848143
Description
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration.
Recommendations
For Cortex XSOAR version 5.5.0, update to a build later than 98621 to resolve the issue.
For Cortex XSOAR version 6.0.1, update to a build later than 830029 to resolve the issue.
For Cortex XSOAR version 6.0.2, update to a build later than 98623 to resolve the issue.
For Cortex XSOAR version 6.1.0, update to a build later than 848144 to resolve the issue.
As a temporary workaround, consider restricting access to the '/var/log/demisto/' server logs to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cortex Xsoar