- Description
- A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
- Source
- talos-cna@cisco.com
- NVD status
- Analyzed
- Products
- lasso
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- talos-cna@cisco.com
- CWE-843
- Hype score
- Not currently trending
CVE-2025-47151: Entr'ouvert Lasso type confusion RCE (CVSS 9.8). SAML implementation library vulnerable via crafted XML parsing. SSO infrastructure bugs enable lateral movement across federated environments. Patch: https://t.co/YATuDUzyJa
@gothburz
15 Nov 2025
91 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-47151 (CVSS:9.8, CRITICAL) is Analyzed. A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 ..https://t.co/imA3C3avqG #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
10 Nov 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-47151: CRITICAL] Type confusion in Entr'ouvert Lasso 2.5.1 and 2.8.2 allows attackers to execute arbitrary code via crafted SAML response, exploiting lasso_node_impl_init_from_xml vulnerability.#cve,CVE-2025-47151,#cybersecurity https://t.co/uD0701bIMf https://t.co/nZY8
@CveFindCom
5 Nov 2025
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-47151 Type Confusion Vulnerability in Entr'ouvert Lasso 2.5.1 and 2.8.2 Enables Arbitrary Code Execution https://t.co/VGvL3HGsgL
@VulmonFeeds
5 Nov 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
**CVE-2025-47151** is a **type confusion vulnerability** found within the `lasso_node_impl_init_from_xml` function of **Entr'ouvert Lasso versions 2.5.1 and 2.8.2**. It allows an attacker who can send a **malformed SAML response** (Security Assertion Markup Language, often used
@CveTodo
5 Nov 2025
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-47151 A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response c… https://t.co/4KVyoLlYtf
@CVEnew
5 Nov 2025
189 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:entrouvert:lasso:2.5.1:*:*:*:*:*:*:*",
"matchCriteriaId": "7177DC8A-9874-45BA-BC80-17604D8A0875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:entrouvert:lasso:2.8.2:*:*:*:*:*:*:*",
"matchCriteriaId": "6418EA3D-B50B-4F83-AA49-D2E2C2710DEA",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]