Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-3034— Cortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logs

CVSS 5.1 · Medium EPSS 0.03% · P8
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-3034

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logs
Source: NVD (National Vulnerability Database)
Vulnerability Description
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2 builds earlier than 98623; Cortex XSOAR 6.1.0 builds earlier than 848144.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
通过日志文件的信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Palo Alto Cortex XSOAR 日志信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Palo Alto Cortex XSOAR是美国 (Palo Alto)公司的一个应用软件。提供安全编排,自动化和响应平台,带有威胁情报管理和内置市场。 Cortex XSOAR software 存在日志信息泄露漏洞,该漏洞源于存在通过日志文件漏洞暴露的信息。以下产品及版本受到影响:Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Palo Alto NetworksCortex XSOAR 5.5.0 ~ 98622 -

II. Public POCs for CVE-2021-3034

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-3034

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2021-3034

No comments yet


Leave a comment