CVE-2018-20857: Input Validation
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a nameid node with user@example.com followed by <!---->. and then the attacker's domain name.
Other sources
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a nameid node with user@example.com followed by <!---->. and then the attacker's domain name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20857.
What is the title of the vulnerability?
The title of the vulnerability is "Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by `<!---->`. and then the attacker's domain name."
What is the severity of CVE-2018-20857?
The severity of CVE-2018-20857 is high with a severity value of 7.5.
How does CVE-2018-20857 affect Zendesk Samlr?
CVE-2018-20857 affects Zendesk Samlr versions before 2.6.2.
Is there a fix available for CVE-2018-20857?
Yes, the fix for CVE-2018-20857 is available in version 2.6.2 of Zendesk Samlr.