漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PAN-OS: Improper SAML SSO authorization of shared local users
Vulnerability Description
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All versions of PAN-OS 8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
Palo Alto Networks PAN-OS 授权问题漏洞
Vulnerability Description
Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS中存在授权问题漏洞。攻击者可借助特制请求利用该漏洞绕过身份验证并获取资源访问权限。以下产品及版本受到影响:PAN-OS 7.1.26之前的7.1.x版本,8.0所有版本,8.1.13之前的8.1.x版本,9.0.6之前的9.0.x版本,9.1.1之前的9.1.x版本。
CVSS Information
N/A
Vulnerability Type
N/A