Podatność w module Mendix SAML umożliwia nieuwierzytelnionemu atakującemu zdalne ominięcie mechanizmu uwierzytelnienia i uzyskanie dostępu do aplikacji. Jest to niekompletna poprawka dla CVE-2023-25957, dotycząca specyficznej, niestandardowej konfiguracji.
▸ Pokaż oryginał (EN)
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.3.1 < V3.6.1), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML (Mendix 9 latest compatible, Upgrade Track) (All versions >= V3.3.0 < V3.6.0), Mendix SAML (Mendix 9 latest compatible, Upgrade Track) (All versions >= V3.1.8 < V3.3.0), Mendix SAML (Mendix 9.12/9.18 compatible, New Track) (All versions >= V3.3.1 < V3.3.15), Mendix SAML (Mendix 9.12/9.18 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.14), Mendix SAML (Mendix 9.6 compatible, New Track) (All versions >= V3.1.9 < V3.2.7), Mendix SAML (Mendix 9.6 compatible, Upgrade Track) (All versions >= V3.1.8 < V3.2.6). The affected versions of the module insufficiently verify the SAML assertions. This could allow unauthenticated remote attackers to bypass authentication and get access to the application. This CVE entry describes the incomplete fix for CVE-2023-25957 in a specific non default configuration.
Dotknięte wersje modułu Mendix SAML w niewystarczający sposób weryfikują asercje SAML przesyłane podczas procesu logowania (CWE-303, CWE-287). Błędna implementacja weryfikacji pozwala na przesłanie spreparowanych asercji SAML, które są akceptowane przez aplikację bez prawidłowego potwierdzenia ich autentyczności. W efekcie atakujący może skutecznie podszywać się pod dowolnego użytkownika bez znajomości jego poświadczeń.
Atakujący uzyskuje nieautoryzowany dostęp do aplikacji opartej na platformie Mendix, potencjalnie z poziomem uprawnień dowolnego użytkownika, co zagraża poufności i integralności danych przetwarzanych przez aplikację.
Należy zaktualizować moduł Mendix SAML do wersji poprawionych wskazanych przez producenta: V1.18.0 lub V1.17.3 (Mendix 7), V2.4.0 lub V2.3.0 (Mendix 8), V3.6.1 lub V3.3.1 (Mendix 9 New Track), V3.6.0 lub V3.3.0 (Mendix 9 Upgrade Track), V3.3.15 (Mendix 9.12/9.18 New Track), V3.3.14 (Mendix 9.12/9.18 Upgrade Track), V3.2.7 (Mendix 9.6 New Track), V3.2.6 (Mendix 9.6 Upgrade Track). Szczegóły dostępne w biuletynie Siemens ProductCERT SSA-851884.
Mendix SAML (Mendix 7 compatible) >= V1.16.4 < V1.18.0; Mendix SAML (Mendix 8 compatible) >= V2.2.0 < V2.4.0; Mendix SAML (Mendix 9 latest compatible, New Track) >= V3.1.9 < V3.6.1; Mendix SAML (Mendix 9 latest compatible, Upgrade Track) >= V3.1.8 < V3.6.0; Mendix SAML (Mendix 9.12/9.18 compatible, New Track) >= V3.3.1 < V3.3.15; Mendix SAML (Mendix 9.12/9.18 compatible, Upgrade Track) >= V3.3.0 < V3.3.14; Mendix SAML (Mendix 9.6 compatible, New Track) >= V3.1.9 < V3.2.7; Mendix SAML (Mendix 9.6 compatible, Upgrade Track) >= V3.1.8 < V3.2.6
Podatność stanowi niekompletną poprawkę dla CVE-2023-25957 i dotyczy wyłącznie specyficznej, niestandardowej konfiguracji modułu Mendix SAML. Administratorzy, którzy wcześniej wdrożyli poprawkę dla CVE-2023-25957, powinni zweryfikować, czy ich konfiguracja wymaga dodatkowej aktualizacji.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMendix Saml
APPMendix1.16.4 – 1.18.0 (bez)2.2.0 – 2.4.0 (bez)3.1.8 – 3.6.1 (bez)
Powiązane podatności
Mendix SAML – pominięcie uwierzytelnienia przez niewystarczającą weryfikację asercji SAML
Reflected XSS w module Mendix SAML umożliwiający kradzież danych
Mendix SAML — niekompletna ochrona przed atakiem replay (CVE-2022-44457)
Mendix SAML — pominięcie uwierzytelnienia przez replay attack
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mend...