GHSA-3w4h-g9f5-j84p

Suggest an improvement
Source
https://github.com/advisories/GHSA-3w4h-g9f5-j84p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3w4h-g9f5-j84p/GHSA-3w4h-g9f5-j84p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3w4h-g9f5-j84p
Aliases
Published
2026-05-28T18:30:32Z
Modified
2026-07-07T16:11:05Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Casdoor does not validate the AudienceRestriction element in SAML assertions
Details

In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T18:37:12Z",
    "nvd_published_at":  "2026-05-28T17:16:34Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/casdoor/casdoor

Package

Name
github.com/casdoor/casdoor
View open source insights on deps.dev
Purl
pkg:golang/github.com/casdoor/casdoor

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.1000.1-0.20260321120606-239e8bd69487

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3w4h-g9f5-j84p/GHSA-3w4h-g9f5-j84p.json"