There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a remote, authenticated attacker who is able to intercept and modify a SAML assertion to impersonate another account (XML Signature Wrapping Attack). In addition patching, Esri also strongly recommends as best practice for SAML assertions to be signed and encrypted.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 10 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Esri
Published: 2021-10-01T14:41:33.989Z
Updated: 2025-04-10T14:59:54.052Z
Reserved: 2021-03-23T00:00:00.000Z
Link: CVE-2021-29108
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-03T22:02:50.492Z
 NVD
                        NVD
                    Status : Modified
Published: 2021-10-01T15:15:07.697
Modified: 2024-11-21T06:00:44.067
Link: CVE-2021-29108
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow