CVE-2020-26276

Published: Dic 17, 2020 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2022-1220 Aliases: GHSA-w3wf-cfx3-6gcx
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 10,0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high
MEDIUM 6,8
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP. Users that configure Fleet with SSO login may be vulnerable to this issue. This issue is patched in 3.5.1. The fix was made using https://github.com/mattermost/xml-roundtrip-validator If upgrade to 3.5.1 is not possible, users should disable SSO authentication in Fleet.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0098
Percentile
0,8th
Updated

EPSS Score Trend (Last 90 Days)

290

Authentication Bypass by Spoofing

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Fleet by Fleetdm

Version Range Affected
To 3.5.1 (exclusive)
cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/fleetdm/fleet/blob/master/CHANGELOG.md#fleet-351-dec-14-2020
https://github.com/fleetdm/fleet/commit/57812a532e5f749c8e18c6f6a652eca65c083607
https://github.com/fleetdm/fleet/security/advisories/GHSA-w3wf-cfx3-6gcx
https://github.com/mattermost/xml-roundtrip-validator
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities
https://github.com/fleetdm/fleet/blob/master/CHANGELOG.md#fleet-351-dec-14-2020
https://github.com/fleetdm/fleet/commit/57812a532e5f749c8e18c6f6a652eca65c083607
https://github.com/fleetdm/fleet/security/advisories/GHSA-w3wf-cfx3-6gcx
https://github.com/mattermost/xml-roundtrip-validator
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities