Vulnerability Description
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fusionauth | Saml V2 | < 0.5.4 |
Related Weaknesses (CWE)
References
- https://github.com/FusionAuth/fusionauth-samlv2/commit/c66fb689d50010662f705d5b5PatchThird Party Advisory
- https://github.com/FusionAuth/fusionauth-samlv2/compare/0.5.3...0.5.4PatchThird Party Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-03_CSNC-2021ExploitThird Party Advisory
- https://github.com/FusionAuth/fusionauth-samlv2/commit/c66fb689d50010662f705d5b5PatchThird Party Advisory
- https://github.com/FusionAuth/fusionauth-samlv2/compare/0.5.3...0.5.4PatchThird Party Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-03_CSNC-2021ExploitThird Party Advisory
FAQ
What is CVE-2021-27736?
CVE-2021-27736 is a vulnerability with a CVSS score of 6.5 (MEDIUM). FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers.DocumentBuilderFactory unsafely.
How severe is CVE-2021-27736?
CVE-2021-27736 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27736?
Check the references section above for vendor advisories and patch information. Affected products include: Fusionauth Saml V2.