Vulnerability Description
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grafana | Grafana | < 6.7.5 |
| Saml Project | Saml | < 0.4.3 |
| Redhat | Openshift Container Platform | 3.11 |
| Redhat | Openshift Service Mesh | 2.0 |
| Redhat | Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 32 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1907670Issue TrackingPatchThird Party Advisory
- https://github.com/crewjam/saml/security/advisories/GHSA-4hq8-gmxx-h6w9Third Party Advisory
- https://grafana.com/blog/2020/12/17/grafana-6.7.5-7.2.3-and-7.3.6-released-with-Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210205-0002/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1907670Issue TrackingPatchThird Party Advisory
- https://github.com/crewjam/saml/security/advisories/GHSA-4hq8-gmxx-h6w9Third Party Advisory
- https://grafana.com/blog/2020/12/17/grafana-6.7.5-7.2.3-and-7.3.6-released-with-Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210205-0002/Third Party Advisory
FAQ
What is CVE-2020-27846?
CVE-2020-27846 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, ...
How severe is CVE-2020-27846?
CVE-2020-27846 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-27846?
Check the references section above for vendor advisories and patch information. Affected products include: Grafana Grafana, Saml Project Saml, Redhat Openshift Container Platform, Redhat Openshift Service Mesh, Redhat Enterprise Linux.