CVE-2021-28091: High severity entrovert lasso vulnerability
Published Jun 4, 2021
·Updated
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Affected Software
6 affected componentsFixes available
debian/lasso
2.6.0-2+deb10u12.6.1-32.8.1-1
Entrouvert Lasso<2.7.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Event History
Jun 4, 2021
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28091?
CVE-2021-28091 is a vulnerability in Lasso versions prior to 2.7.0 that allows improper verification of a cryptographic signature.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker to bypass cryptographic verification and potentially gain unauthorized access.
3
What is the severity of CVE-2021-28091?
The severity of CVE-2021-28091 is high with a CVSS severity score of 7.5.
4
Which software versions are affected by CVE-2021-28091?
Lasso versions prior to 2.7.0 are affected.
5
How do I fix CVE-2021-28091?
To fix CVE-2021-28091, it is recommended to upgrade to Lasso version 2.7.0 or newer.