First published: Fri Jul 26 2019(Updated: )
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by `<!---->`. and then the attacker's domain name.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zendesk Samlr | <2.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-20857.
The title of the vulnerability is "Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by `<!---->`. and then the attacker's domain name."
The severity of CVE-2018-20857 is high with a severity value of 7.5.
CVE-2018-20857 affects Zendesk Samlr versions before 2.6.2.
Yes, the fix for CVE-2018-20857 is available in version 2.6.2 of Zendesk Samlr.