PT-2022-16038 · Unknown · Passport-Wsfed-Saml2

Gkwang

·

Published

2022-12-13

·

Updated

2023-07-14

·

CVE-2022-23505

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Passport-wsfed-saml2 versions prior to 4.6.3
Description A remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the attacker is in possession of an arbitrary IDP signed assertion. Depending on the IDP used, fully unauthenticated attacks might also be feasible if generation of a signed message can be triggered.
Recommendations Upgrade the library to version 4.6.3. As a temporary workaround, consider using SAML2 authentication instead of WSFed until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-23505
GHSA-PPJQ-QXHX-M25F

Affected Products

Passport-Wsfed-Saml2