CVE-2025-47151: Critical severity Entr'ouvert Lasso vulnerability
A type confusion vulnerability exists in the lassonodeimplinitfromxml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47151?
CVE-2025-47151 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2025-47151?
To mitigate CVE-2025-47151, upgrade Entr'ouvert Lasso to a version that is not affected by this vulnerability.
What software is affected by CVE-2025-47151?
CVE-2025-47151 affects Entr'ouvert Lasso versions 2.5.1 and 2.8.2.
What kind of attack exploits CVE-2025-47151?
CVE-2025-47151 can be exploited by sending a specially crafted SAML response to the application.
What are the consequences of CVE-2025-47151 being exploited?
If exploited, CVE-2025-47151 can lead to arbitrary code execution, compromising the affected system.