There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
References
Configurations
History
29 Jun 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-347 | |
Summary | There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted. | |
References |
|
Information
Published : 2021-10-01 15:15
Updated : 2023-06-29 14:15
NVD link : CVE-2021-29108
Mitre link : CVE-2021-29108
JSON object : View
Products Affected
esri
- portal_for_arcgis
CWE
CWE-347
Improper Verification of Cryptographic Signature