PT-2022-20545 · Wire · Wire
Published
2022-10-18
·
Updated
2022-10-20
·
CVE-2022-31122
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wire versions prior to 2022-07-12/Chart 4.19.0
Description
The issue allows an attacker to delete all SAML authenticated accounts of a targeted team, authenticate as a user of the attacked team, and create arbitrary accounts in the context of the team if it is not managed by SCIM. This can be achieved if the attacker has certain details of SAML IdP metadata and configures their own SAML on the same backend.
Recommendations
For versions prior to 2022-07-12/Chart 4.19.0, update to version 2022-07-12/Chart 4.19.0 to resolve the issue.
As a temporary workaround, consider disabling SAML configuration for teams by setting
galley.config.settings.featureFlags.sso to false, which can reduce the risk of an attack.
Note that the ability to configure SAML SSO as a team is disabled by default for on-premise installations.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wire