脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
UAA accepts SAML Encrypted Assertions authentication bypass
脆弱性説明
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. Encryption uses the SP's public key from published metadata, therefore, any party, not only a trusted IdP, can produce ciphertext UAA can decrypt; successful decryption therefore does not prove the IdP issued the message. Affected versions: Cloud Foundry UAA (uaa_release) 2.0.0 through 78.13.0. Cloud Foundry CF Deployment all versions through 56.1.0.
CVSS情報
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
脆弱性タイプ
密码学签名的验证不恰当
脆弱性タイトル
Cloud Foundry UAA和CloudFoundry CF Deployment 数据伪造问题漏洞
脆弱性説明
Cloud Foundry UAA是美国Cloud Foundry基金会的一款应用于CloudFoundry云平台的身份验证和管理服务终端。CloudFoundry CF Deployment 是CloudFoundry基金会的一个代码部署组件。 Cloud Foundry UAA 2.0.0至78.13.0版本和CloudFoundry CF Deployment 56.1.0及之前版本存在数据伪造问题漏洞,该漏洞源于错误将XML加密视为签名替代,可能导致接受未签名但加密的断言。
CVSS情報
N/A
脆弱性タイプ
N/A