PT-2018-5219 · Samlify+1 · Samlify+1

Thijsschoonbrood

·

Published

2018-01-02

·

Updated

2018-01-17

·

CVE-2017-1000452

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions samlify versions prior to 2.4.0-rc5 Express-saml2 (affected versions not specified) samlify version 2.2.0 and earlier
Description An issue exists that could allow attackers to impersonate arbitrary users by modifying SAML content for a SAML service provider without invalidating the cryptographic signature. This may allow attackers to bypass primary authentication for the affected SAML service provider. The issue is due to the failure to prevent XML Signature Wrapping, allowing tokens to be reused with different usernames.
Recommendations For samlify versions prior to 2.4.0-rc5, upgrade to version 2.4.0-rc5 or later. For Express-saml2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to SAML service providers to minimize the risk of exploitation.

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1000452
GHSA-8JJF-W7J6-323C

Affected Products

Express-Saml2
Samlify