Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01cDh3LTJtdnctMzhwds4AAvTF
Signature bypass via multiple root elements
Impact
A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered.
Patches
Users should upgrade to node-saml v4.0.0-beta5 or newer.
Workarounds
Disable SAML authentication.
References
Are there any links users can visit to find out more?
For more information
If you have any questions or comments about this advisory:
- Open a discussion in the node-saml repo
Credits
- Felix Wilhelm of Google Project Zero
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01cDh3LTJtdnctMzhwds4AAvTF
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 12 months ago
Updated: 8 months ago
CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-5p8w-2mvw-38pv, CVE-2022-39300
References:
- https://github.com/node-saml/node-saml/security/advisories/GHSA-5p8w-2mvw-38pv
- https://github.com/node-saml/node-saml/commit/c1f275c289c01921e58f5c70ce0fdbc5287e5fbe
- https://nvd.nist.gov/vuln/detail/CVE-2022-39300
- https://github.com/advisories/GHSA-5p8w-2mvw-38pv
Affected Packages
npm:node-saml
Versions: < 4.0.0-beta.5Fixed in: 4.0.0-beta.5