simplesamlphp/saml2 is vulnerable to Authentication Bypass
81
High Risk
The HTTP-Artifact binding accepts an embedded SAML Response without verifying its signature when that response is unsigned. The receive path returns the unsigned embedded message before reaching signature verification and never binds the embedded response issuer to the artifact issuer, so a party controlling one federated identity provider can wrap an unsigned response claiming to originate from a different identity provider. The response is then treated as successfully received, allowing authentication as arbitrary users of a higher-trust identity provider. The fix makes embedded-response signature verification mandatory and rejects responses whose issuer does not match the resolved identity provider.
You are affected if you are using a version that falls within the vulnerable range and you use the HTTP-Artifact binding in a multi-identity-provider federation and rely on the binding to authenticate the embedded response.
simplesamlphp/saml2 is vulnerable to Authentication Bypass in versions 6.2.2 - 6.2.3.
Upgrade the simplesamlphp/saml2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant