Type Confusion Vulnerability in Entr'ouvert Lasso Software
CVE-2025-47151
9.6CRITICAL
What is CVE-2025-47151?
A type confusion vulnerability affects the lasso_node_impl_init_from_xml functionality within Entr'ouvert Lasso versions 2.5.1 and 2.8.2. This flaw allows an attacker to exploit a specially crafted SAML response, which could result in arbitrary code execution. By sending a malformed SAML response, malicious actors can trigger this vulnerability, potentially breaching application security and compromising sensitive data.
Affected Version(s)
Lasso 2.5.1
Lasso 2.8.2
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Keane O'Kelley of and another member of Cisco Advanced Security Initiative Group
