Description
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console intervention.
References
https://security.nozominetworks.com/NN-2023:7-01
Vendor Advisory
https://security.nozominetworks.com/NN-2023:7-01
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
4.9 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2023-08-09T08:15:09.687Z
2 years agoLast modified
2024-11-21T06:47:04.113Z
1 year ago