CVE-2022-31261

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
24/05/2022
Last modified:
08/06/2022

Description

An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A remote attacker can send a request crafted with an XXE payload to invoke a malicious DTD hosted on a system that they control. This results in reading local files that the application has access to.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:morpheusdata:morpheus:*:*:*:*:*:*:*:* 5.2.16 (including)
cpe:2.3:a:morpheusdata:morpheus:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.4 (including)