Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HaloITSM - SAML XML Signature Wrapping (XSW)
Vulnerability Description
HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
HaloITSM 安全漏洞
Vulnerability Description
HaloITSM是英国HaloITSM公司的一款符合 ITIL 的 ITSM 软件。 HaloITSM 2.146.1版本及之前版本存在安全漏洞,该漏洞源于受到SAML XML签名包装漏洞的影响,配置SAML集成后,匿名参与者只需知道电子邮件地址即可冒充任意HaloITSM用户。
CVSS Information
N/A
Vulnerability Type
N/A