Start with Identity
Identity CVE · IGA

CVE-2024-3319SailPoint ISC RCE via transform templates

critical
Product: SailPoint Identity Security CloudVendor: SailPointDisclosed: 2024-04-10Status: PatchedNVD ↗

What broke

ISC transform templates evaluated attacker-influenced expressions in a way that became code execution. SailPoint patched the SaaS side. Same class as Conjur's Ruby template injection.

Why it matters

Transforms are how IGA maps HR data onto accounts. Giving that language an eval is how a governance product becomes a foothold in the tenant that governs everyone else.

What to do

  • Confirm SailPoint's fix in your tenant.
  • Restrict who can edit transforms. That permission is equivalent to code execution on the IGA plane.
  • Review custom transforms for unexpected expressions after any contractor or high-priv session.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.