VDB
Sign up
CRITICAL9.1

GHSA-h3rw-77w7-92gf

Samly access control vulnerability

Quick fix

GHSA-h3rw-77w7-92gf — Samly: upgrade to the fixed version with the command below.

mix deps.update Samly

Details

In the Samly package before 1.4.0 for Elixir, `Samly.State.Store.get_assertion/3` can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/Samly
Introduced in: 0Fixed in: 1.4.0
Fixmix deps.update Samly

References