First published: Tue Jul 30 2024(Updated: )
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
Credit: security@puppet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Perforce Akana API | <=2024.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5249 has a medium severity rating.
To fix CVE-2024-5249, upgrade to Akana API Platform version 2024.1.0 or later.
CVE-2024-5249 affects Akana API Platform versions prior to 2024.1.0.
The main issue with CVE-2024-5249 is that SAML tokens can be replayed, leading to potential unauthorized access.
There is no documented workaround for CVE-2024-5249; the only mitigation is upgrading to the latest version.