GHSA-8gqj-226h-gm8r
Passport-wsfed-saml2 allows SAML Authentication Bypass via Attribute Smuggling
Quick fix
GHSA-8gqj-226h-gm8r — passport-wsfed-saml2: upgrade to the fixed version with the command below.
npm install passport-wsfed-saml2@4.6.4Details
### Overview This vulnerability allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response. This can be done by adding attributes to the response.
### Am I Affected? You are affected by this SAML Attribute Smuggling vulnerability if you are using `passport-wsfed-saml2` version 4.6.3 or below, specifically under the following conditions: 1. The service provider is using `passport-wsfed-saml2`, 2. A valid SAML Response signed by the Identity Provider can be obtained
### Fix Upgrade to v4.6.4 or greater.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.5Fixed in: 4.6.4npm install passport-wsfed-saml2@4.6.4