Description
fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to forged assertions if f MDM enrollment is enabled. This vulnerability is fixed in 4.64.2, 4.63.2, 4.62.4, and 4.58.1.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/fleetdm/fleet/security/advisories/GHSA-52jx-g6m5-h735
Patch x_refsource_misc
https://github.com/fleetdm/fleet/commit/718c95e47ad010ad6b8ceb3f3460e921fbfc53bb
Scores
CVSS v4
9.3
EPSS
0.0014
EPSS Percentile
33.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-285
Status
published
Products (5)
fleetdm/fleet
4.64.0 - 4.64.2Go
fleetdm/fleet
< 4.58.1
fleetdm/fleet
>= 4.62.0, < 4.62.4
fleetdm/fleet
>= 4.63.0, < 4.63.2
fleetdm/fleet
>= 4.64.0, < 4.64.2
Published
Mar 06, 2025
Tracked Since
Feb 18, 2026