Products
Akana API Platform
- before 2024.1.0
Source
security@puppet.com
Tags
CVE-2024-5249 details
Published : July 30, 2024, 7:15 p.m.
Last Modified : July 30, 2024, 7:15 p.m.
Last Modified : July 30, 2024, 7:15 p.m.
Description
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
CVSS Score
1 | 2 | 3 | 4 | 5.4 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-294 | Authentication Bypass by Capture-replay | A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes). |
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Base Score
5.4
Exploitability Score
2.8
Impact Score
2.5
Base Severity
MEDIUM
Vector String : CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
References
URL | Source |
---|---|
https://portal.perforce.com/s/detail/a91PA000001SUH7YAO | security@puppet.com |
This website uses the NVD API, but is not approved or certified by it.