PT-2022-16116 · Fleet+1 · Fleet+1
Iangcarroll
·
Published
2022-02-04
·
Updated
2024-12-25
·
CVE-2022-23600
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fleet versions prior to 4.9.1
Description
The issue exposes a limited ability to spoof SAML authentication with missing audience verification, impacting deployments using SAML SSO in two specific cases. A malicious or compromised Service Provider (SP) could reuse the SAML response to log into Fleet as a user, if the user has an account with the same email in Fleet and signs into the malicious SP via SAML SSO from the same Identity Provider (IdP) configured with Fleet. Additionally, a user with an account in Fleet could reuse a SAML response intended for another SP to log into Fleet, if the user is blocked from Fleet in the IdP but continues to have an account in Fleet.
Recommendations
For versions prior to 4.9.1:
Reduce the length of sessions on your IdP to reduce the window for malicious re-use.
Limit the amount of SAML Service Providers/Applications used by user accounts with access to Fleet.
When removing access to Fleet in the IdP, delete the Fleet user from Fleet as well.
For the best resolution, upgrade to Fleet 4.9.1.
Exploit
Fix
Improper Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Fleet