CVE-2017-1000452

HIGH7.5EPSS 0.14%

Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames

Published: 1/4/2018Modified: 11/8/2023
Also known as:GHSA-8jjf-w7j6-323c

Description

Versions of `samlify` prior to 2.4.0-rc5 are vulnerable to Authentication Bypass. The package fails to prevent XML Signature Wrapping, allowing tokens to be reused with different usernames. A remote attacker can modify SAML content for a SAML service provider without invalidating the cryptographic signature, which may allow attackers to bypass primary authentication for the affected SAML service provider. ## Recommendation Upgrade to version 2.4.0-rc5 or later

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References (7)