8.1

CVE-2022-39300

Signature bypass via multiple root elements in node-SAML

node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to node-saml version 4.0.0-beta5 or newer. Disabling SAML authentication may be done as a workaround.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Node Saml Project ≫ Node Saml SwPlatform node.js Version < 4.0.0
Node Saml Project ≫ Node Saml Version 4.0.0 Update beta0 SwPlatform node.js
Node Saml Project ≫ Node Saml Version 4.0.0 Update beta1 SwPlatform node.js
Node Saml Project ≫ Node Saml Version 4.0.0 Update beta2 SwPlatform node.js
Node Saml Project ≫ Node Saml Version 4.0.0 Update beta3 SwPlatform node.js
Node Saml Project ≫ Node Saml Version 4.0.0 Update beta4 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.48
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 7.7 2.2 5.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://github.com/node-saml/node-saml/commit/c1f275c289c01921e58f5c70ce0fdbc5287e5fbe
Patch
Third Party Advisory
https://github.com/node-saml/node-saml/security/advisories/GHSA-5p8w-2mvw-38pv
Third Party Advisory