CVE-2021-28091
published 2021-06-04CVE-2021-28091: Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.32%
68.1th percentile
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | lasso | < lasso 2.6.1-3 (bookworm) | lasso 2.6.1-3 (bookworm) |
| entrouvert | lasso | < 2.7.0 | 2.7.0 |
| entrouvert | lasso | >= 0 < 2.6.1-3 | 2.6.1-3 |
| entrouvert | lasso | >= 0 < 2.6.1-3 | 2.6.1-3 |
| entrouvert | lasso | >= 0 < 2.6.1-3 | 2.6.1-3 |
| entrouvert | lasso | >= 0 < 2.6.1-3 | 2.6.1-3 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_lasso_2.8.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_cisco8.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
vendor_msrc·2021-06-08·CVSS 7.5
CVE-2021-28091 [HIGH] CWE-347 Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner
Ubuntu
Lasso vulnerability
vendor_ubuntu·2021-06-02
CVE-2021-28091 Lasso vulnerability
Title: Lasso vulnerability
Summary: Applications using Lasso could be made to allow unintended access.
It was discovered that Lasso did not properly verify that all
assertions in a SAML response were properly signed. An attacker
could possibly use this to impersonate users or otherwise bypass
access controls.
Instructions: After a standard system update you need to restart applications that use
Lasso to make all the necessary changes.
Cisco
Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021
vendor_cisco·2021-06-01·CVSS 8.8
CVE-2021-28091 [HIGH] CWE-269 Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021
Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021
On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library. This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.
For a description of this vulnerability, see lasso.git NEWS.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD
Red Hat
lasso: XML signature wrapping vulnerability when parsing SAML responses
vendor_redhat·2021-06-01·CVSS 7.5
CVE-2021-28091 [HIGH] CWE-347 lasso: XML signature wrapping vulnerability when parsing SAML responses
lasso: XML signature wrapping vulnerability when parsing SAML responses
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
An XML Signature Wrapping (XSW) vulnerability was found in Lasso. This flaw allows an attacker to modify a valid SAML response to include an unsigned SAML assertion, which may be used to impersonate another valid user recognized by the service using Lasso. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.
Statement: Lasso is provided in Red Hat Enterprise Linux 7, and 8 only as a dependency of mod_auth_mellon, without development files. The way mod_auth_mellon uses Lasso makes it not vulnerable to this flaw, because SAML responses are additionally validated to h
Debian
CVE-2021-28091: lasso - Lasso all versions prior to 2.7.0 has improper verification of a cryptographic s...
vendor_debian·2021·CVSS 7.5
CVE-2021-28091 [HIGH] CVE-2021-28091: lasso - Lasso all versions prior to 2.7.0 has improper verification of a cryptographic s...
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Scope: local
bookworm: resolved (fixed in 2.6.1-3)
bullseye: resolved (fixed in 2.6.1-3)
forky: resolved (fixed in 2.6.1-3)
sid: resolved (fixed in 2.6.1-3)
trixie: resolved (fixed in 2.6.1-3)
Cisco
Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021
vendor_cisco·CVSS 3.1
CVE-2021-28091 Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021
CVE-2021-28091: Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021
On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library. This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application. For a description of this vulnerability, see lasso.git NEWS . This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD
CVSS: 3.1
CWE: CWE-269, CWE-269
Bug IDs: CSCvx73154, CSCvx73164, CSCvx73156, CSCvx73154, CSCvx73164
GHSA
GHSA-5pxh-5p72-wvcm: Lasso all versions prior to 2
ghsa_unreviewed·2022-05-24
CVE-2021-28091 [HIGH] CWE-347 GHSA-5pxh-5p72-wvcm: Lasso all versions prior to 2
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
OSV
CVE-2021-28091: Lasso all versions prior to 2
osv·2021-06-04·CVSS 7.5
CVE-2021-28091 [HIGH] CVE-2021-28091: Lasso all versions prior to 2
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://listes.entrouvert.com/arc/lasso/https://git.entrouvert.org/lasso.git/commit/?id=076a37d7f0eb74001127481da2d355683693cde9https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0https://lists.debian.org/debian-lts-announce/2021/06/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SI4YAQF4VEV2KHQ6OXXZL7CJK7IZQ3EG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSVWOHBBWLI2RB5C6TXINFEJRT4YSD3D/https://www.debian.org/security/2021/dsa-4926http://listes.entrouvert.com/arc/lasso/https://git.entrouvert.org/lasso.git/commit/?id=076a37d7f0eb74001127481da2d355683693cde9https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0https://lists.debian.org/debian-lts-announce/2021/06/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SI4YAQF4VEV2KHQ6OXXZL7CJK7IZQ3EG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSVWOHBBWLI2RB5C6TXINFEJRT4YSD3D/https://www.debian.org/security/2021/dsa-4926
2021-06-04
Published