PT-2022-16038 · Unknown · Passport-Wsfed-Saml2
Gkwang
·
Published
2022-12-13
·
Updated
2023-07-14
·
CVE-2022-23505
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Passport-wsfed-saml2 versions prior to 4.6.3
Description
A remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the attacker is in possession of an arbitrary IDP signed assertion. Depending on the IDP used, fully unauthenticated attacks might also be feasible if generation of a signed message can be triggered.
Recommendations
Upgrade the library to version 4.6.3.
As a temporary workaround, consider using SAML2 authentication instead of WSFed until the issue is resolved.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Passport-Wsfed-Saml2