Entr'ouvert Lasso
cpe:2.3:a:entrouvert:lasso:*:*:*:*:*:*:*
- 2.5.1
A denial-of-service vulnerability has been identified in Entr'ouvert Lasso version 2.5.1, specifically within the 'lasso_node_init_from_message_with_format' function. This vulnerability arises when a specially crafted SAML response is processed, leading to memory exhaustion and causing a denial-of-service condition. The issue can be triggered by sending a malformed SAML response to the application.
Exploitation of this vulnerability leads to memory depletion, causing a denial-of-service condition where the application becomes unresponsive or unavailable.
Users can update to the patched version of Entr'ouvert Lasso released on August 12, 2025.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.