CVE-2021-29108: There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.
There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for the privilege escalation vulnerability in Esri Portal for ArcGIS?
The vulnerability ID is CVE-2021-29108.
What is the severity of CVE-2021-29108?
The severity of CVE-2021-29108 is high with a CVSS score of 8.8.
Which versions of Esri Portal for ArcGIS are affected by CVE-2021-29108?
Esri Portal for ArcGIS versions 10.9 and below are affected by CVE-2021-29108.
What is the impact of CVE-2021-29108?
CVE-2021-29108 allows a remote, authenticated attacker to impersonate another account through an XML Signature Wrapping Attack.
Are there any patches or updates available for CVE-2021-29108?
Yes, there is a patch available for CVE-2021-29108. Please refer to the references section for more information.