CVE-2021-3034: Cortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logs
An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO) integration can be logged to the '/var/log/demisto/' server logs when testing the integration during setup. This logged information includes the private key and identity provider certificate used to configure the SAML SSO integration. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 98622; Cortex XSOAR 6.0.1 builds earlier than 830029; Cortex XSOAR 6.0.2 builds earlier than 98623; Cortex XSOAR 6.1.0 builds earlier than 848144.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cortex XSOARto a version that resolves this vulnerability.Fixed in 5.5.0 build 98622 - Upgrade
Upgrade
Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.0.1 build 830029 - Upgrade
Upgrade
Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.0.2 build 98623 - Upgrade
Upgrade
Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.1.0 build 848144 - Operational
After upgrading Cortex XSOAR, configure a new private key for the SAML SSO integration (because the prior private key may have been logged to '/var/log/demisto/' during setup testing).
- Operational
Clear the server system logs using the Workarounds and Mitigations section instructions to remove any potentially logged SAML SSO secrets from '/var/log/demisto/'.
Event History
Frequently Asked Questions
What is CVE-2021-3034?
CVE-2021-3034 is an information exposure through log file vulnerability in Cortex XSOAR software.
How does CVE-2021-3034 impact Cortex XSOAR software?
CVE-2021-3034 exposes secrets configured for the SAML single sign-on (SSO) integration to the server logs.
What is the severity of CVE-2021-3034?
CVE-2021-3034 has a severity rating of medium with a severity value of 5.1.
Which versions of Cortex XSOAR are affected by CVE-2021-3034?
Cortex XSOAR versions 5.5.0 to 5.5.0-94592, 6.0.1 to 6.0.1-81077, 6.0.2 to 6.0.2-97682, and 6.1.0 are affected by CVE-2021-3034.
How can I fix CVE-2021-3034 in Cortex XSOAR software?
To fix CVE-2021-3034, update Cortex XSOAR software to a version that is not affected by the vulnerability.