First published: Fri Aug 13 2021(Updated: )
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange SAML | <1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36786 is a vulnerability in the miniorange_saml (aka Miniorange Saml) extension before version 1.4.3 for TYPO3 that allows Sensitive Data Exposure of API credentials and private keys.
The miniorange_saml (aka Miniorange Saml) extension before version 1.4.3 for TYPO3 is affected by CVE-2021-36786.
CVE-2021-36786 has a severity level of 7.5 (High).
To fix CVE-2021-36786, update the miniorange_saml (aka Miniorange Saml) extension to version 1.4.3 or later.
You can find more information about CVE-2021-36786 at the TYPO3 security advisories page (https://typo3.org/security/advisory/typo3-ext-sa-2021-011).