Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Cortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logs
Vulnerability Description
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2 builds earlier than 98623; Cortex XSOAR 6.1.0 builds earlier than 848144.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Palo Alto Cortex XSOAR 日志信息泄露漏洞
Vulnerability Description
Palo Alto Cortex XSOAR是美国 (Palo Alto)公司的一个应用软件。提供安全编排,自动化和响应平台,带有威胁情报管理和内置市场。 Cortex XSOAR software 存在日志信息泄露漏洞,该漏洞源于存在通过日志文件漏洞暴露的信息。以下产品及版本受到影响:Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2
CVSS Information
N/A
Vulnerability Type
N/A