vulnerability

FreeBSD: VID-417de1e6-c31b-11eb-9633-b42e99a1b9c3 (CVE-2021-28091): lasso -- signature checking failure

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Jun 1, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

entrouvert reports: When AuthnResponse messages are not signed (which is permitted by the specifiation), all assertion's signatures should be checked, but currently after the first signed assertion is checked all following assertions are accepted without checking their signature, and the last one is considered the main assertion.

Solution

freebsd-upgrade-package-lasso
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.