Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aviatrix Systems Controller 数据伪造问题漏洞
Vulnerability Description
Aviatrix Systems Controller是美国Aviatrix Systems公司的一款用于Aviatrix Systems解决方案的业务流程和管理的集中控制面板。 Aviatrix Systems Controller 5.1及之前版本中存在安全漏洞。攻击者可借助身份提供者(IDP)的任何已签名的SAML断言利用该漏洞建立连接。
CVSS Information
N/A
Vulnerability Type
N/A