GHSA-7fpw-cfc4-3p2c
Dashboard / Vulnerabilities / GHSA-7fpw-cfc4-3p2c
GHSA-7fpw-cfc4-3p2c
Summary: Duplicate advisory: High severity vulnerability that affects passport-wsfed-saml2
Details: ## Duplicate advisory This advisory has been withdrawn because it is a duplicate of GHSA-77fw-rf4v-vfp9. This link is maintained to preserve external references. ## Original Description A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16897, https://auth0.com/docs/security/bulletins/cve-2017-16897, https://github.com/advisories/GHSA-7fpw-cfc4-3p2c
Affected packages
Package
Name: passport-wsfed-saml2
Purl: pkg:npm/passport-wsfed-saml2
Affected ranges
Type: SEMVER
Events:
