GHSA-8jjf-w7j6-323c

    Dashboard / Vulnerabilities / GHSA-8jjf-w7j6-323c

    GHSA-8jjf-w7j6-323c

    Published: 4 Jan 2018Last Modified: 8 Nov 2023

    Summary: Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames

    Details: Versions of `samlify` prior to 2.4.0-rc5 are vulnerable to Authentication Bypass. The package fails to prevent XML Signature Wrapping, allowing tokens to be reused with different usernames. A remote attacker can modify SAML content for a SAML service provider without invalidating the cryptographic signature, which may allow attackers to bypass primary authentication for the affected SAML service provider. ## Recommendation Upgrade to version 2.4.0-rc5 or later

    Affected packages

    Package

    Name: samlify

    Purl: pkg:npm/samlify

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.4.0-rc5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High