passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.3%
probabilidad de explotación
0.3%top 80% de las CVE
explotación observada
noninguna fuente lo reporta
passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
krakenjs · passport-saml-encryptedReferencias
https://github.com/krakenjs/passport-saml-encryptedhttps://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L296https://github.com/krakenjs/passport-saml-encrypted/blob/v0.1.13/lib/saml.js#L321https://github.com/krakenjs/passport-saml-encrypted/issues/29https://www.vulncheck.com/advisories/passport-saml-encrypted-through-0.1.13-authentication-bypass-via-missing-signature-verification