Количество 2
Количество 2
CVE-2026-9093
In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.
GHSA-3w4h-g9f5-j84p
Casdoor does not validate the AudienceRestriction element in SAML assertions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9093 In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor. | CVSS3: 9.8 | 0% Низкий | 2 месяца назад | |
GHSA-3w4h-g9f5-j84p Casdoor does not validate the AudienceRestriction element in SAML assertions | CVSS3: 9.8 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу