PT-2021-18715 · Palo Alto Networks · Cortex Xsoar

Martin Spielmann

+1

·

Published

2021-03-10

·

Updated

2021-03-24

·

CVE-2021-3034

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cortex XSOAR versions 5.5.0 through 5.5.0 build 98621 Cortex XSOAR versions 6.0.1 through 6.0.1 build 830028 Cortex XSOAR versions 6.0.2 through 6.0.2 build 98622 Cortex XSOAR versions 6.1.0 through 6.1.0 build 848143
Description An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration.
Recommendations For Cortex XSOAR version 5.5.0, update to a build later than 98621 to resolve the issue. For Cortex XSOAR version 6.0.1, update to a build later than 830029 to resolve the issue. For Cortex XSOAR version 6.0.2, update to a build later than 98623 to resolve the issue. For Cortex XSOAR version 6.1.0, update to a build later than 848144 to resolve the issue. As a temporary workaround, consider restricting access to the '/var/log/demisto/' server logs to minimize the risk of exploitation.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3034

Affected Products

Cortex Xsoar