PT-2025-45110 · Unknown+8 · Entr’Ouvert Lasso+8
Keane Okelley
·
Published
2025-11-05
·
Updated
2025-12-08
·
CVE-2025-47151
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Entr'ouvert Lasso versions 2.5.1 and 2.8.2
Description
A type confusion issue exists within the
lasso node impl init from xml function. A specially crafted SAML response can trigger this issue, potentially leading to arbitrary code execution. An attacker can exploit this by sending a malformed SAML response. The vulnerability resides within the SAML implementation library and impacts Single Sign-On (SSO) infrastructure, potentially enabling lateral movement across federated environments.Recommendations
Versions prior to 2.5.1 and versions after 2.8.2 should be considered for use.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Entr’Ouvert Lasso
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu