PT-2022-24883 · Node-Saml+1 · Node-Saml+1

Felix Wilhelm

·

Published

2022-10-12

·

Updated

2022-10-14

·

CVE-2022-39300

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions node-saml versions prior to 4.0.0-beta5
Description A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks might also be feasible if generation of a signed message can be triggered.
Recommendations For versions prior to 4.0.0-beta5, upgrade to node-saml version 4.0.0-beta5 or newer. As a temporary workaround, consider disabling SAML authentication until a patch is available.

Exploit

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2022-39300
GHSA-5P8W-2MVW-38PV

Affected Products

Node-Saml
Passport-Saml