CVE-2020-26276
In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Fleet is an open source osquery manager. In Fleet before version 3.5.1, due to issues in Go's standard library XML parsing, a valid SAML response may be mutated by an attacker to modify the trusted document. This can result in allowing unverified logins from a SAML IdP. Users that configure Fleet with SSO login may be vulnerable to this issue. This issue is patched in 3.5.1. The fix was made using https://github.com/mattermost/xml-roundtrip-validator If upgrade to 3.5.1 is not possible, users should disable SSO authentication in Fleet.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.20% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- fleetdm/fleet
- Source
- security-advisories@github.com
References
- https://github.com/fleetdm/fleet/blob/master/CHANGELOG.md#fleet-351-dec-14-2020Release Notes, Third Party Advisory
- https://github.com/fleetdm/fleet/commit/57812a532e5f749c8e18c6f6a652eca65c083607Patch, Third Party Advisory
- https://github.com/fleetdm/fleet/security/advisories/GHSA-w3wf-cfx3-6gcxThird Party Advisory
- https://github.com/mattermost/xml-roundtrip-validatorThird Party Advisory
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilitiesNot Applicable, Third Party Advisory
- https://github.com/fleetdm/fleet/blob/master/CHANGELOG.md#fleet-351-dec-14-2020Release Notes, Third Party Advisory
- https://github.com/fleetdm/fleet/commit/57812a532e5f749c8e18c6f6a652eca65c083607Patch, Third Party Advisory
- https://github.com/fleetdm/fleet/security/advisories/GHSA-w3wf-cfx3-6gcxThird Party Advisory
- https://github.com/mattermost/xml-roundtrip-validatorThird Party Advisory
- https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilitiesNot Applicable, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.