A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered.
Users should upgrade to node-saml v4.0.0-beta5 or newer.
Disable SAML authentication.
Are there any links users can visit to find out more?
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-347"
],
"github_reviewed": true,
"github_reviewed_at": "2022-10-12T22:05:44Z",
"nvd_published_at": "2022-10-13T22:15:00Z",
"severity": "HIGH"
}