There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Esri
Published: 2021-10-01T14:41:33.989383Z
Updated: 2024-09-16T16:48:34.344Z
Reserved: 2021-03-23T00:00:00
Link: CVE-2021-29108
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-10-01T15:15:07.697
Modified: 2024-11-21T06:00:44.067
Link: CVE-2021-29108
Redhat
No data.