Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.1
CVE-2026-53424
- EPSS -
- Veröffentlicht 20.08.2026 17:27:11
- Zuletzt bearbeitet 20.08.2026 19:16:54
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:valid...
7.6
CVE-2026-53425
- EPSS -
- Veröffentlicht 20.08.2026 17:26:35
- Zuletzt bearbeitet 20.08.2026 19:16:54
Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_ha...
9.8
CVE-2024-25718
- EPSS 0.66%
- Veröffentlicht 11.02.2024 05:15:08
- Zuletzt bearbeitet 21.11.2024 09:01:16
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.
1