Improper Privilege Management in Lasso - CVE-2021-28091
Published: June 1, 2021
Vulnerability identifier: #VU53725
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28091
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to impersonate other users.
The vulnerability exists due to improper privilege management within Lasso SAML implementation. A remote authenticated user can impersonate other authorized application users while interacting with the application.
Affected software
Lasso
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
Fedora
lasso (Debian package)
python-lasso (Ubuntu package)
python3-lasso (Ubuntu package)
liblasso3 (Ubuntu package)
liblasso-perl (Ubuntu package)
lasso (Red Hat package)
python3-lasso
liblasso3
liblasso-devel
lasso
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
Fedora
lasso (Debian package)
python-lasso (Ubuntu package)
python3-lasso (Ubuntu package)
liblasso3 (Ubuntu package)
liblasso-perl (Ubuntu package)
lasso (Red Hat package)
python3-lasso
liblasso3
liblasso-devel
lasso
How to mitigate CVE-2021-28091
Install updates from vendor's website.
Lasso - update to 2.7.0
lasso (Debian package) - update to 2.6.0-2+deb10u1
python-lasso (Ubuntu package) - update to 2.5.1-0ubuntu1.2
python3-lasso (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
liblasso3 (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
liblasso-perl (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
lasso (Red Hat package) - addressed in versions 2.5.1-8.el7_9, 2.6.0-12.el8
python3-lasso - update to 2.6.1-8.7.2
liblasso3 - update to 2.6.1-8.7.2
liblasso-devel - update to 2.6.1-8.7.2
lasso - addressed in versions 2.7.0-1.fc33, 2.7.0-1.fc34, 2.7.0-1.fc35
lasso (Debian package) - update to 2.6.0-2+deb10u1
python-lasso (Ubuntu package) - update to 2.5.1-0ubuntu1.2
python3-lasso (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
liblasso3 (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
liblasso-perl (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
lasso (Red Hat package) - addressed in versions 2.5.1-8.el7_9, 2.6.0-12.el8
python3-lasso - update to 2.6.1-8.7.2
liblasso3 - update to 2.6.1-8.7.2
liblasso-devel - update to 2.6.1-8.7.2
lasso - addressed in versions 2.7.0-1.fc33, 2.7.0-1.fc34, 2.7.0-1.fc35
External References
Related Security Bulletins
- Improper privilege management in Lasso SAML
- Debian update for lasso
- Red Hat Enterprise Linux 7 update for lasso
- Amazon Linux AMI update for lasso
- SUSE update for lasso
- Ubuntu update for lasso
- Red Hat Enterprise Linux 8 update for lasso
- Fedora 35 update for lasso
- Fedora 33 update for lasso
- Fedora 34 update for lasso