5
CVSSv2

CVE-2012-2351

Published: 12/07/2012 Updated: 07/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The default configuration of the auth/saml plugin in Mahara prior to 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 6.0

mahara mahara 1.4

mahara mahara 1.3.3

mahara mahara 1.2.6

mahara mahara 1.2.0

mahara mahara 1.1.1

mahara mahara 1.1.0

mahara mahara 1.1.7

mahara mahara 1.1.8

mahara mahara 1.1

mahara mahara 1.0.9

mahara mahara 1.0.6

mahara mahara 1.0.14

mahara mahara 1.0.15

mahara mahara 0.9.1

mahara mahara 0.9.2

mahara mahara 1.3.0

mahara mahara 1.3.1

mahara mahara 1.2.2

mahara mahara 1.1.6

mahara mahara 1.0.0

mahara mahara 1.0.4

mahara mahara 1.0.3

mahara mahara 1.0.1

mahara mahara

mahara mahara 1.3.4

mahara mahara 1.3.6

mahara mahara 1.2.4

mahara mahara 1.2.5

mahara mahara 1.1.5

mahara mahara 1.1.4

mahara mahara 1.0.5

mahara mahara 1.0.7

mahara mahara 1.0.10

mahara mahara 1.0.11

mahara mahara 0.9.0

mahara mahara 1.4.0

mahara mahara 1.3.8

mahara mahara 1.3.7

mahara mahara 1.3.5

mahara mahara 1.3.2

mahara mahara 1.2.1

mahara mahara 1.2.3

mahara mahara 1.1.2

mahara mahara 1.1.9

mahara mahara 1.1.3

mahara mahara 1.0.8

mahara mahara 1.0.2

mahara mahara 1.0.12

mahara mahara 1.0.13

Vendor Advisories

It was discovered that Mahara, the portfolio, weblog, and resume builder, had an insecure default with regards to SAML-based authentication used with more than one SAML identity provider Someone with control over one IdP could impersonate users from other IdP's For the stable distribution (squeeze), this problem has been fixed in version 126-2+ ...