MEDIUM6.8
GHSA-mfcp-34xw-p57x
Authentication Bypass in saml2-js
Quick fix
GHSA-mfcp-34xw-p57x — saml2-js: upgrade to the fixed version with the command below.
npm install saml2-js@2.0.5Details
Versions of `saml2-js` prior to 2.0.5 are vulnerable to an Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.
## Recommendation
Upgrade to version 2.0.5 or later.
Are you affected?
Enter the version of the package you're using.