PT-2021-22429 · Unknown · Passport-Saml
Pp-Ps
·
Published
2021-08-27
·
Updated
2021-09-07
·
CVE-2021-39171
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Passport-SAML versions prior to 3.1.0
Description
A malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service. This would be an effective way to perform a denial-of-service attack.
Recommendations
For versions prior to 3.1.0, update to version 3.1.0 to resolve the issue by limiting the number of allowable transforms to 2. As a temporary workaround, consider restricting the processing of SAML payloads to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Passport-Saml