CRITICAL9.1
GHSA-h3rw-77w7-92gf
Samly access control vulnerability
Quick fix
GHSA-h3rw-77w7-92gf — Samly: upgrade to the fixed version with the command below.
mix deps.update SamlyDetails
In the Samly package before 1.4.0 for Elixir, `Samly.State.Store.get_assertion/3` can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-25718[ADVISORY]
- https://github.com/dropbox/samly/pull/13[WEB]
- https://github.com/dropbox/samly/pull/13/commits/812b5c3ad076dc9c9334c1a560c8e6470607d1eb[WEB]
- https://github.com/dropbox/samly/commit/7637ebeef6c6b88ec2032f5323c32edcebbacbc6[WEB]
- https://diff.hex.pm/diff/samly/1.3.0..1.4.0[WEB]
- https://github.com/dropbox/samly[PACKAGE]
- https://github.com/handnot2/samly[WEB]
- https://hex.pm/packages/samly[WEB]