VDB
Sign up
MEDIUM6.8

GHSA-mfcp-34xw-p57x

Authentication Bypass in saml2-js

Quick fix

GHSA-mfcp-34xw-p57x — saml2-js: upgrade to the fixed version with the command below.

npm install saml2-js@2.0.5

Details

Versions of `saml2-js` prior to 2.0.5 are vulnerable to an Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.

## Recommendation

Upgrade to version 2.0.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/saml2-js
Introduced in: 0Fixed in: 2.0.5
Fixnpm install saml2-js@2.0.5

References