A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
2020-12-21T16:15:13.067
2024-11-21T05:21:55.503
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | grafana | grafana | < 6.7.5 | Yes |
Application | grafana | grafana | < 7.2.3 | Yes |
Application | grafana | grafana | < 7.3.6 | Yes |
Application | saml_project | saml | < 0.4.3 | Yes |
Application | redhat | openshift_container_platform | 3.11 | Yes |
Application | redhat | openshift_container_platform | 4.0 | Yes |
Application | redhat | openshift_service_mesh | 2.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | fedoraproject | fedora | 32 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |