Dropbox

Samly

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 17:27:11
  • Zuletzt bearbeitet 20.08.2026 19:16:54

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:valid...

  • EPSS -
  • Veröffentlicht 20.08.2026 17:26:35
  • Zuletzt bearbeitet 20.08.2026 19:16:54

Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_ha...

  • EPSS 0.66%
  • Veröffentlicht 11.02.2024 05:15:08
  • Zuletzt bearbeitet 21.11.2024 09:01:16

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.