Improper Authentication in SAML library for go - CVE-2022-41912
Published: January 4, 2023
Vulnerability identifier: #VU70697
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41912
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing SAML responses containing multiple Assertion elements. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
SAML library for go
Red Hat OpenShift Container Platform
Grafana
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Ceph Storage
Storage Ceph
Red Hat OpenShift Container Platform
Grafana
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Ceph Storage
Storage Ceph
How to mitigate CVE-2022-41912
Install updates from vendor's website.
SAML library for go - update to 0.4.9
Red Hat OpenShift Container Platform - addressed in versions 4.8.57, 4.9.55, 4.10.47, 4.11.21
Grafana - addressed in versions 8.5.20, 9.2.8, 9.3.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.7.0
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
Red Hat OpenShift Container Platform - addressed in versions 4.8.57, 4.9.55, 4.10.47, 4.11.21
Grafana - addressed in versions 8.5.20, 9.2.8, 9.3.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.3, 2.7.0
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
External References
Related Security Bulletins
- Authentication bypass in SAML library for go
- OpenShift Container Platform 4.11 update for SAML library for go
- OpenShift Container Platform 4.10 update for golang
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- Privilege escalation in Grafana SAML integration
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes
- Multiple vulnerabilities in OpenShift Container Platform 4.9
- Multiple vulnerabilities in Red Hat Ceph Storage
- Improper authentication in IBM Storage Ceph
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6