There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Esri
Published: 2021-10-01T14:41:33.989Z
Updated: 2025-04-10T14:59:54.052Z
Reserved: 2021-03-23T00:00:00.000Z
Link: CVE-2021-29108
Updated: 2024-08-03T22:02:50.492Z
Status : Modified
Published: 2021-10-01T15:15:07.697
Modified: 2024-11-21T06:00:44.067
Link: CVE-2021-29108
No data.
ReportizFlow