VDB
Sign up
HIGH8.1

GHSA-5p8w-2mvw-38pv

Signature bypass via multiple root elements

Quick fix

GHSA-5p8w-2mvw-38pv — node-saml: upgrade to the fixed version with the command below.

npm install node-saml@4.0.0-beta.5

Details

### Impact

A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered.

### Patches

Users should upgrade to node-saml v4.0.0-beta5 or newer.

### Workarounds

Disable SAML authentication.

### References _Are there any links users can visit to find out more?_

### For more information If you have any questions or comments about this advisory: * Open a discussion in the [node-saml repo](https://github.com/node-saml/node-saml/discussions)

### Credits

* Felix Wilhelm of Google Project Zero

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-saml
Introduced in: 0Fixed in: 4.0.0-beta.5
Fixnpm install node-saml@4.0.0-beta.5

References