漏洞信息详情
Lasso 数据伪造问题漏洞
漏洞简介
Lasso是一个eBay开源Node.js-style的JavaScript 模块捆绑器。该工具提供了许多不同的优化,例如捆绑、代码拆分、延迟加载、条件依赖等。
Lasso SAML存在安全漏洞,该漏洞源于Lasso SAML 的权限管理不当形成。通过远程身份验证的用户在与应用程序交互时可以冒充其他授权的应用程序用户。该漏洞允许攻击者冒充其他用户。受影响的产品和版本如下:Lasso:0.2.0、0.3.0、0.4.0、0.4。 1, 0.5.0, 0.6.0, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 1.9.9, 2.0.0, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.2.90, 2.2.91, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.4. 0、2.4.1、2.5.0、2.5.1、2.6.0、2.6.1。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0
参考网址
来源:MISC
链接:https://git.entrouvert.org/lasso.git/commit/?id=076a37d7f0eb74001127481da2d355683693cde9
来源:MISC
链接:http://listes.entrouvert.com/arc/lasso/
来源:MISC
链接:https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4926
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/06/msg00013.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/YSVWOHBBWLI2RB5C6TXINFEJRT4YSD3D/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/SI4YAQF4VEV2KHQ6OXXZL7CJK7IZQ3EG/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021080214
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164855/Red-Hat-Security-Advisory-2021-4325-03.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060502
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1952
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163723/Red-Hat-Security-Advisory-2021-2989-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2105
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3799
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-28091
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2595
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021090830
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1895
来源:tools.cisco.com
链接:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1895.3
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Lasso-privilege-escalation-via-Unsigned-AuthnResponse-Messages-Assertion-35575
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162912/Ubuntu-Security-Notice-USN-4974-1.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060144
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1895.2
受影响实体
暂无
补丁
- Lasso 数据伪造问题漏洞的修复措施<!--2021-6-1-->
还没有评论,来说两句吧...