Releases37
Frequency1 month 3 weeks
Last Release
Stars315
PowerShell module for CyberArk Privileged Access Security REST API

CVE History

CVEPublishedCVSS v3CVSS v2
3.1 LOW

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An unauthenticated attacker in a 'Man-in-the-Middle' position could manipulate the TLS handshake and downgrade TLS to a deprecated protocol. Fixed in 7.0.209.