PT-2025-19969 · Auth0 · Passport-Wsfed-Saml2

Kevinroh-Okta

·

Published

2025-05-06

·

Updated

2025-10-16

·

CVE-2025-46572

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions passport-wsfed-saml2 versions 3.0.5 through 4.6.3
Description A vulnerability in passport-wsfed-saml2 allows an attacker to impersonate any user in the Auth0 tenant during SAML authentication by crafting a SAMLResponse. This can be done by using a valid SAML object that was signed by the configured IdP. Users are affected specifically when the service provider is using passport-wsfed-saml2 and a valid SAML document signed by the Identity Provider can be obtained.
Recommendations For versions 3.0.5 through 4.6.3, update to version 4.6.4 to resolve the issue. As a temporary workaround, consider restricting access to SAML authentication until the update is applied. Avoid using the SAMLResponse object in the affected authentication flow until the issue is resolved.

Exploit

Fix

Improper Authentication

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2025-46572
GHSA-WJMP-WPHQ-JVQF

Affected Products

Passport-Wsfed-Saml2