已在以下 Mendix SAML 模块版本中发现漏洞: 适用于 Mendix 10 的 Mendix SAML 模块(所有低于 V4.2.3 的版本) 适用于 Mendix 11 的 Mendix SAML 模块(所有低于 V4.2.3 的版本) 适用于 Mendix 9.24 的 Mendix SAML 模块(所有低于 V3.6.27 的版本) 受影响版本的模块未能正确验证 SAML 响应签名。在特定的 SSO 配置下,未经身份验证的远程攻击者可能借此劫持用户账户(会话)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Siemens | Mendix SAML (Mendix 10 compatible) | < V4.2.3 |
affected |
| Siemens | Mendix SAML (Mendix 11 compatible) | < V4.2.3 |
affected |
| Siemens | Mendix SAML (Mendix 9.24 compatible) | < V3.6.27 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Siemens | Mendix SAML (Mendix 10 compatible) | 0 ~ V4.2.3 | - |
|
| Siemens | Mendix SAML (Mendix 11 compatible) | 0 ~ V4.2.3 | - |
|
| Siemens | Mendix SAML (Mendix 9.24 compatible) | 0 ~ V3.6.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet