Extension WordPress
Vulnérabilités OneLogin SAML SSO
Cette page rassemble les failles publiées pour OneLogin SAML SSO, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de OneLogin SAML SSO
5 fiches
OneLogin SAML SSO <= 3.1.2 – Open Redirection
The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. This makes it possible for unauthorized attackers to redirect traffic to potentially malicious websites.
*-3.1.2
3.2.0
31/03/2021
OneLogin SAML SSO <= 2.8.0 – Distributed Denial-of-Service
The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML Entity Expansion. This makes it possible for unauthenticated attackers to use XML External Entity to…
*-2.8.0
3.0.0
28/01/2019
OneLogin SAML SSO <= 2.4.2 – Use of Vulnerable Component
The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.
*-2.4.2
2.4.3
14/10/2016
OneLogin SAML-SSO Plugin < 2.1.6 – Authentication Bypass
The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in the ~/onelogin-saml-sso/onelogin_saml.php file in versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create new accounts,…
[*, 2.1.6)
2.1.6
06/06/2016
OneLogin SAML SSO < 2.2.0 – Authentication Bypass
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
[*, 2.2.0)
2.2.0
21/01/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.