PT-2018-5219 · Samlify+1 · Samlify+1
Thijsschoonbrood
·
Published
2018-01-02
·
Updated
2018-01-17
·
CVE-2017-1000452
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
samlify versions prior to 2.4.0-rc5
Express-saml2 (affected versions not specified)
samlify version 2.2.0 and earlier
Description
An issue exists that could allow attackers to impersonate arbitrary users by modifying SAML content for a SAML service provider without invalidating the cryptographic signature. This may allow attackers to bypass primary authentication for the affected SAML service provider. The issue is due to the failure to prevent XML Signature Wrapping, allowing tokens to be reused with different usernames.
Recommendations
For samlify versions prior to 2.4.0-rc5, upgrade to version 2.4.0-rc5 or later.
For Express-saml2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to SAML service providers to minimize the risk of exploitation.
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Express-Saml2
Samlify