Entrouvert Lasso vulnerabilities

7 known vulnerabilities affecting entrouvert/lasso.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-47151CRITICALCVSS 9.8v2.5.1v2.8.22025-11-05
CVE-2025-47151 [CRITICAL] CWE-843 CVE-2025-47151: A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39 A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
nvdosv
CVE-2025-46404HIGHCVSS 7.5v2.5.12025-11-05
CVE-2025-46404 [HIGH] CWE-476 CVE-2025-46404: A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality o A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
nvdosv
CVE-2025-46705HIGHCVSS 7.5v2.5.1v2.8.22025-11-05
CVE-2025-46705 [HIGH] CWE-617 CVE-2025-46705: A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouver A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
nvdosv
CVE-2025-46784HIGHCVSS 7.5v2.5.12025-11-05
CVE-2025-46784 [HIGH] CWE-401 CVE-2025-46784: A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionali A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
nvdosv
CVE-2021-28091HIGHCVSS 7.5fixed in 2.7.02021-06-04
CVE-2021-28091 [HIGH] CWE-347 CVE-2021-28091: Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
nvdosv
CVE-2015-1783HIGHCVSS 7.5≤ 2.4.02017-08-11
CVE-2015-1783 [HIGH] CWE-119 CVE-2015-1783: The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c9 The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
nvdosv
CVE-2009-0050MEDIUMCVSS 4.3≤ 2.2.1-0v1.9.9.0+1 more2009-01-07
CVE-2009-0050 [MEDIUM] CVE-2009-0050: Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify functio Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
nvdosv