Improper Privilege Management in Lasso - CVE-2021-28091

 

Improper Privilege Management in Lasso - CVE-2021-28091

Published: June 1, 2021


Vulnerability identifier: #VU53725
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28091
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to impersonate other users.

The vulnerability exists due to improper privilege management within Lasso SAML implementation. A remote authenticated user can impersonate other authorized application users while interacting with the application.


Affected software

Lasso
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
Fedora
lasso (Debian package)
python-lasso (Ubuntu package)
python3-lasso (Ubuntu package)
liblasso3 (Ubuntu package)
liblasso-perl (Ubuntu package)
lasso (Red Hat package)
python3-lasso
liblasso3
liblasso-devel
lasso

How to mitigate CVE-2021-28091

Install updates from vendor's website.

Lasso - update to 2.7.0
lasso (Debian package) - update to 2.6.0-2+deb10u1
python-lasso (Ubuntu package) - update to 2.5.1-0ubuntu1.2
python3-lasso (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
liblasso3 (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
liblasso-perl (Ubuntu package) - addressed in versions 2.5.1-0ubuntu1.2, 2.6.0-7ubuntu1.2, 2.6.0-7ubuntu2.1, 2.6.1-2ubuntu0.1
lasso (Red Hat package) - addressed in versions 2.5.1-8.el7_9, 2.6.0-12.el8
python3-lasso - update to 2.6.1-8.7.2
liblasso3 - update to 2.6.1-8.7.2
liblasso-devel - update to 2.6.1-8.7.2
lasso - addressed in versions 2.7.0-1.fc33, 2.7.0-1.fc34, 2.7.0-1.fc35

External References

Related Security Bulletins