PT-2025-13434 · Unknown+1 · Opensaml C++ Library+1

Published

2025-03-16

·

Updated

2025-06-06

·

CVE-2025-31335

CVSS v3.1

4.0

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSAML C++ library versions prior to 3.3.1
Description The issue allows forging of signed SAML messages via parameter manipulation when using SAML bindings that rely on non-XML signatures.
Recommendations For versions prior to 3.3.1, update to version 3.3.1 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-31335
DLA-4093-1
DSA-5879-1
OPENSUSE-SU-2025:14959-1
OPENSUSE-SU-2025_1500-1
SUSE-SU-2025:01500-1
SUSE-SU-2025:1500-1
SUSE-SU-2025:1501-1
SUSE-SU-2025_01500-1
SUSE-SU-2025_1500-1
SUSE-SU-2025_1501-1
USN-7364-1

Affected Products

Opensaml C++ Library
Suse