Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vw3m-3x7w-24g8

Опубликовано: 10 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

EPSS

Процентиль: 20%
0.00271
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.1
nvd
13 дней назад

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to receive authenticated profiles without valid signatures.

EPSS

Процентиль: 20%
0.00271
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-347