REDHAT-BUG-2412739: Entr'ouvert Lasso vulnerability
A type confusion vulnerability exists in the lassonodeimplinitfromxml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2412739?
REDHAT-BUG-2412739 has a high severity due to its potential for arbitrary code execution.
How do I fix REDHAT-BUG-2412739?
To fix REDHAT-BUG-2412739, update to a patched version of Entr'ouvert Lasso that addresses this vulnerability.
What products are affected by REDHAT-BUG-2412739?
REDHAT-BUG-2412739 affects Entr'ouvert Lasso versions 2.5.1 and 2.8.2.
What kind of vulnerability is REDHAT-BUG-2412739?
REDHAT-BUG-2412739 is a type confusion vulnerability that can be exploited through malformed SAML responses.
Can REDHAT-BUG-2412739 lead to system compromise?
Yes, exploiting REDHAT-BUG-2412739 can lead to arbitrary code execution and potential system compromise.