Логотип exploitDog
bind:CVE-2025-47949
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-47949

Количество 2

Количество 2

nvd логотип

CVE-2025-47949

9 месяцев назад

samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider. Version 2.10.0 fixes the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r683-v43c-6xqv

9 месяцев назад

samlify SAML Signature Wrapping attack

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-47949

samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider. Version 2.10.0 fixes the issue.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-r683-v43c-6xqv

samlify SAML Signature Wrapping attack

0%
Низкий
9 месяцев назад

Уязвимостей на страницу