GHSA-mfcp-34xw-p57x

Suggest an improvement
Source
https://github.com/advisories/GHSA-mfcp-34xw-p57x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-mfcp-34xw-p57x/GHSA-mfcp-34xw-p57x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mfcp-34xw-p57x
Published
2020-09-03T21:20:52Z
Modified
2021-09-29T20:12:42Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Authentication Bypass in saml2-js
Details

Versions of saml2-js prior to 2.0.5 are vulnerable to an Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.

Recommendation

Upgrade to version 2.0.5 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:51:27Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / saml2-js

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-mfcp-34xw-p57x/GHSA-mfcp-34xw-p57x.json"