XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.
References
Link | Resource |
---|---|
https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacks | Exploit Technical Description Third Party Advisory |
https://my.topdesk.com/tas/public/ssp/content/detail/knowledgeitem?unid=56a16ba1c2824e9a82655892ba75d3c0 | Permissions Required |
https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacks | Exploit Technical Description Third Party Advisory |
https://my.topdesk.com/tas/public/ssp/content/detail/knowledgeitem?unid=56a16ba1c2824e9a82655892ba75d3c0 | Permissions Required |
Configurations
History
21 Nov 2024, 08:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacks - Exploit, Technical Description, Third Party Advisory | |
References | () https://my.topdesk.com/tas/public/ssp/content/detail/knowledgeitem?unid=56a16ba1c2824e9a82655892ba75d3c0 - Permissions Required |
30 Jun 2023, 16:20
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-863 | |
First Time |
Topdesk
Topdesk topdesk |
|
References | (MISC) https://my.topdesk.com/tas/public/ssp/content/detail/knowledgeitem?unid=56a16ba1c2824e9a82655892ba75d3c0 - Permissions Required | |
References | (MISC) https://char49.com/articles/topdesk-vulnerable-to-xml-signature-wrapping-attacks - Exploit, Technical Description, Third Party Advisory | |
CPE | cpe:2.3:a:topdesk:topdesk:12.10.12:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
22 Jun 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-22 19:15
Updated : 2024-11-21 08:07
NVD link : CVE-2023-34923
Mitre link : CVE-2023-34923
CVE.ORG link : CVE-2023-34923
JSON object : View
Products Affected
topdesk
- topdesk
CWE
CWE-863
Incorrect Authorization