Entrouvert
Entrouvert Lasso: vulnerabilidades y CVE
Entrouvert Lasso tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28156 | Alta (8.5) | 0.36% | — | 13 ago 2026 | Subscriber SQL Injection in Do Lasso <= 358 versions. |
| CVE-2025-47151 | Crítica (9.8) | 1.1% | — | 5 nov 2025 | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker… |
| CVE-2025-46784 | Alta (7.5) | 0.59% | — | 5 nov 2025 | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in… |
| CVE-2025-46705 | Alta (7.5) | 0.57% | — | 5 nov 2025 | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can… |
| CVE-2025-46404 | Alta (7.5) | 0.59% | — | 5 nov 2025 | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send… |
| CVE-2021-28091 | Alta (7.5) | 1.3% | — | 4 jun 2021 | Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. |
| CVE-2015-1783 | Alta (7.5) | 3.5% | — | 11 ago 2017 | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application… |
| CVE-2009-0050 | Media (4.3) | 1.3% | — | 7 ene 2009 | Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.