PT-2021-22429 · Unknown · Passport-Saml

Pp-Ps

·

Published

2021-08-27

·

Updated

2021-09-07

·

CVE-2021-39171

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Passport-SAML versions prior to 3.1.0
Description A malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service. This would be an effective way to perform a denial-of-service attack.
Recommendations For versions prior to 3.1.0, update to version 3.1.0 to resolve the issue by limiting the number of allowable transforms to 2. As a temporary workaround, consider restricting the processing of SAML payloads to minimize the risk of exploitation.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39171
GHSA-5379-R78W-42H2

Affected Products

Passport-Saml