ZeroHour

CVE-2023-25957

CVSS 3.1
7.5 high
EPSS
<1%p46
Published
()
Modified
Description

A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 = V2.2.0 = V3.1.9 = V3.1.8 = V3.1.9 = V3.1.8 < V3.2.6). The affected versions of the module insufficiently verify the SAML assertions. This could allow unauthenticated remote attackers to bypass authentication and get access to the application. For compatibility reasons, fix versions still contain this issue, but only when the recommended, default configuration option `'Use Encryption'` is disabled.

Vendors
mendix
Products
saml
Weakness
CWE-303, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.