HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://haloitsm.com/guides/article/?kbid=2154 |
History
Thu, 08 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Haloservicesolutions
Haloservicesolutions haloitsm |
|
CPEs | cpe:2.3:a:haloservicesolutions:haloitsm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Haloservicesolutions
Haloservicesolutions haloitsm |
|
Metrics |
ssvc
|
ssvc
|
Wed, 07 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: NCSC.ch
Published: 2024-08-06T06:01:41.415Z
Updated: 2024-08-08T13:43:27.833Z
Reserved: 2024-06-20T13:13:28.976Z
Link: CVE-2024-6202
Vulnrichment
Updated: 2024-08-07T20:42:18.778Z
NVD
Status : Analyzed
Published: 2024-08-06T06:15:35.487
Modified: 2024-08-29T17:48:43.723
Link: CVE-2024-6202
Redhat
No data.