Skip to content
Noroxi

fusionauth records

4 published records for vendor fusionauth.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
25%
Median publish → KEV
No record has entered KEV

All records

4 records
  • FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Sig

    CriticalCVSS 9.1No exploitEPSS 3%

    fusionauth · samlv2Oct 2, 2020

  • CVE-2020-7799
    34Monitor

    An issue was discovered in FusionAuth before 1.11.0.

    HighCVSS 7.2Proof of conceptEPSS 20%

    fusionauth · fusionauthJan 28, 2020

  • FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request.

    HighCVSS 7.5No exploitEPSS 1%

    fusionauth · fusionauthNov 28, 2022

  • FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xm

    MediumCVSS 6.5No exploitEPSS 1%

    fusionauth · saml v2Apr 22, 2021