VDB
Sign up
HIGH8.1

GHSA-m974-647v-whv7

Signature bypass via multiple root elements

Quick fix

GHSA-m974-647v-whv7 — passport-saml: upgrade to the fixed version with the command below.

npm install passport-saml@3.2.2

Details

### Impact

A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered.

### Patches

Users should upgrade to passport-saml 3.2.2 or newer. The issue was also present in the beta releases of `node-saml` before v4.0.0-beta.5.

### Workarounds

Disable SAML authentication.

### References _Are there any links users can visit to find out more?_

### For more information If you have any questions or comments about this advisory: * Open a discussion in the [node-saml repo](https://github.com/node-saml/node-saml/discussions)

### Credits

* Felix Wilhelm of Google Project Zero

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/passport-saml
Introduced in: 0Fixed in: 3.2.2
Fixnpm install passport-saml@3.2.2
npm/node-saml
Introduced in: 0Fixed in: 4.0.0-beta.5
Fixnpm install node-saml@4.0.0-beta.5
npm/@node-saml/node-saml
Introduced in: 0Fixed in: 4.0.0-beta.5
Fixnpm install @node-saml/node-saml@4.0.0-beta.5
npm/@node-saml/passport-saml
Introduced in: 0Fixed in: 4.0.0-beta.3
Fixnpm install @node-saml/passport-saml@4.0.0-beta.3

References