Entr Ouvert Lasso vulnerabilities

4 known vulnerabilities affecting entr_ouvert/lasso.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2025-47151CRITICALCVSS 9.8v2.5.1v2.8.22025-11-05
CVE-2025-47151 [CRITICAL] CWE-843 CVE-2025-47151: A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39 A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
nvd
CVE-2025-46705HIGHCVSS 7.5v2.5.1v2.8.22025-11-05
CVE-2025-46705 [HIGH] CWE-617 CVE-2025-46705: A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouver A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
nvd
CVE-2025-46404HIGHCVSS 7.5v2.5.12025-11-05
CVE-2025-46404 [HIGH] CWE-476 CVE-2025-46404: A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality o A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
nvd
CVE-2025-46784HIGHCVSS 7.5v2.5.12025-11-05
CVE-2025-46784 [HIGH] CWE-401 CVE-2025-46784: A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionali A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
nvd