VYPR

CloudStack SAML 2.0 authentication Service Provider plugin

by Apache

CVEs (1)

  • CVE-2022-35741CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.08

    Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the…