|
|
Subscribe / Log in / New account

mahara: insecure default/privilege escalation

Package(s):mahara CVE #(s):
Created:May 9, 2012 Updated:May 9, 2012
Description:

From the Debian advisory:

It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider. Someone with control over one IdP could impersonate users from other IdP's.

Alerts:
Debian DSA-2467-1 mahara 2012-05-09

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds