
pspete/psPAS
Releases37
Frequency1 month 3 weeks
Last Release
Stars315
PowerShell module for CyberArk Privileged Access Security REST API
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 3.1 LOW | — | ||
psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An unauthenticated attacker in a 'Man-in-the-Middle' position could manipulate the TLS handshake and downgrade TLS to a deprecated protocol. Fixed in 7.0.209. | |||