CVE-2024-47832·Docker vulnerability
ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying mechanism exploits differential behavior between XML parsers. Users of https://ssoready.com, the public hosted instance of SSOReady, are unaffected. We advise folks who self-host SSOReady to upgrade to 7f92a06 or later. Do so by updating your SSOReady Docker images from sha-... to sha-7f92a06. There are no known workarounds for this vulnerability.
- Severity
- critical
- Software
- Docker
- Fixed in
- 2024-10-09
- Published
- 2024-10-09
Affected versions
Until: 2024-10-09
Fixed in: 2024-10-09
How to fix this CVE
Self-hosted SSOReady deployments must update their Docker images to commit 7f92a06 or later to patch a critical XML signature validation flaw that could allow unauthorized authentication bypass. Update your running Docker container images immediately by pulling the latest SSOReady release and redeploying. Cloud-hosted users on ssoready.com are not affected by this vulnerability.
sudo dnf update docker-ceDefensia detects this vulnerability
How to check if you are affected
- Step 1: Run `docker --version` to confirm Docker is installed and note the current version
- Step 2: Run `docker images | grep ssoready` to list all SSOReady container images and their current SHA digests
- Step 3: Compare the running image SHA against the fixed commit 7f92a06 by inspecting the image details with `docker inspect <image_id> | grep -i digest`
- Step 4: After updating, re-run `docker images` and verify the SSOReady image SHA has been updated to reflect the patched commit
FAQ
What is CVE-2024-47832?
CVE-2024-47832 is a critical XML signature bypass vulnerability in self-hosted SSOReady instances that allows attackers to forge authentication tokens by exploiting inconsistencies between XML parser implementations. This could enable unauthorized access to protected resources without valid credentials.
Is CVE-2024-47832 being actively exploited?
No, there are currently no known active exploits or public proof-of-concept code for this vulnerability according to CISA and public security databases.
What versions of Docker are affected by CVE-2024-47832?
This vulnerability affects self-hosted SSOReady instances running Docker images created before October 9, 2024. All versions prior to commit 7f92a06 are vulnerable; the vulnerability was fixed on 2024-10-09.
How do I check if my server is vulnerable to CVE-2024-47832?
Run `docker inspect <ssoready_image> --format='{{.RepoDigests}}'` and verify the digest corresponds to commit 7f92a06 or later. If your image is older than October 9, 2024, you are vulnerable.
Does Defensia detect CVE-2024-47832?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2024-47832 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-47832. Free for 1 server.
Get started free