VDB
Sign up
CRITICAL

GHSA-r683-v43c-6xqv

samlify SAML Signature Wrapping attack

Quick fix

GHSA-r683-v43c-6xqv — samlify: upgrade to the fixed version with the command below.

npm install samlify@2.10.0

Details

A Signature Wrapping attack has been found in samlify <v2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/samlify
Introduced in: 0Fixed in: 2.10.0
Fixnpm install samlify@2.10.0

References