CVE-2020-27846

Aliases:GHSA-4hq8-gmxx-h6w9BIT-grafana-2020-27846GO-2021-0058
Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 21 Dec 2020, 15:16
Last modified:04 Aug 2024, 16:25

Vulnerability Summary

Overall Risk (default)
critical
90/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
7.54% LOW
8% probability -0.19%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

21 Dec 2020, 15:16
Published
Vulnerability first disclosed
04 Aug 2024, 16:25
Last Modified
Vulnerability information updated

Description

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 7.54% Percentile: 92%

Techniques & Countermeasures

  • CWE-115Misinterpretation of Input

    The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.

Affected Systems

  • fedoraprojectfedora

    32 | 33

  • github.com/crewjamsaml

    < 0.4.3

  • grafanagrafana

    < 6.7.5 | ≥ 7.0.0, < 7.2.3 | ≥ 7.3.0, < 7.3.6

  • redhatenterprise_linux

    8.0

  • redhatopenshift_container_platform

    3.11 | 4.0

  • redhatopenshift_service_mesh

    2.0

  • saml_projectsaml

    < 0.4.3

References (16)