A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "0.4.3"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"fixed": "6.7.5"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.2.3"
},
{
"introduced": "7.3.0"
},
{
"fixed": "7.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "4.0"
},
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "33"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-27846.json"