CVE-2012-2351: Medium severity debian linux vulnerability
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2351?
CVE-2012-2351 is considered to have a medium severity level due to potential user impersonation risks.
How do I fix CVE-2012-2351?
To fix CVE-2012-2351, update Mahara to version 1.4.2 or later where the "Match username attribute to Remote username" option is correctly configured.
What versions of Mahara are affected by CVE-2012-2351?
CVE-2012-2351 affects all versions of Mahara prior to 1.4.2, including versions 1.0.0 to 1.4.1.
What is the impact of CVE-2012-2351?
The impact of CVE-2012-2351 allows attackers to spoof users from different SAML IdP servers if they have the same internal username.
Is CVE-2012-2351 a remote vulnerability?
Yes, CVE-2012-2351 is a remote vulnerability that allows exploitation from networked environments without local access.