GHSA-4mh8-9wq6-rjxg
OpenAM vulnerable to user impersonation using SAMLv1.x SSO process
Quick fix
GHSA-4mh8-9wq6-rjxg — org.openidentityplatform.openam:openam-federation-library: upgrade to the fixed version with the command below.
# pom.xml: bump <version>14.7.3</version> for org.openidentityplatform.openam:openam-federation-libraryDetails
### Impact OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process. Attackers can use this fact to impersonate any OpenAM user, including the administrator, by sending a specially crafted SAML response to the SAMLPOSTProfileServlet servlet.
### Patches This problem has been patched in OpenAM 14.7.3-SNAPSHOT and later
### Workarounds One should comment servlet `SAMLPOSTProfileServlet` in web.xml or disable SAML in OpenAM ```xml <servlet> <description>SAMLPOSTProfileServlet</description> <servlet-name>SAMLPOSTProfileServlet</servlet-name> <servlet-class>com.sun.identity.saml.servlet.SAMLPOSTProfileServlet</servlet-class> </servlet> ... <servlet-mapping> <servlet-name>SAMLSOAPReceiver</servlet-name> <url-pattern>/SAMLSOAPReceiver</url-pattern> </servlet-mapping> ```
### References #624
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 14.7.3# pom.xml: bump <version>14.7.3</version> for org.openidentityplatform.openam:openam-federation-libraryReferences
- https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-4mh8-9wq6-rjxg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-37471[ADVISORY]
- https://github.com/OpenIdentityPlatform/OpenAM/pull/624[WEB]
- https://github.com/OpenIdentityPlatform/OpenAM/commit/7c18543d126e8a567b83bb4535631825aaa9d742[WEB]
- https://github.com/OpenIdentityPlatform/OpenAM[PACKAGE]