Lucene search

K
osvGoogleOSV:USN-4974-1
HistoryJun 02, 2021 - 3:15 a.m.

lasso vulnerability

2021-06-0203:15:08
Google
osv.dev
10
lasso
saml
vulnerability
assertion verification
security issue
access control

AI Score

6.6

Confidence

Low

EPSS

0.006

Percentile

78.1%

It was discovered that Lasso did not properly verify that all
assertions in a SAML response were properly signed. An attacker
could possibly use this to impersonate users or otherwise bypass
access controls.