CRITICAL
GHSA-r683-v43c-6xqv
samlify SAML Signature Wrapping attack
Quick fix
GHSA-r683-v43c-6xqv — samlify: upgrade to the fixed version with the command below.
npm install samlify@2.10.0Details
A Signature Wrapping attack has been found in samlify <v2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider.
Are you affected?
Enter the version of the package you're using.