auth0/passport-wsfed-saml2
cpe:2.3:a:auth0:passport-wsfed-saml2:*:*:*:*:*:*:*
- >= 3.0.5, <= 4.6.3
A vulnerability in passport-wsfed-saml2, affecting versions 3.0.5 prior to 4.6.4, allows attackers to impersonate users during SAML authentication by crafting a SAMLResponse. This exploitation involves using a valid SAML object signed by the Identity Provider (IdP). Users are specifically vulnerable when their service provider employs passport-wsfed-saml2 and they can obtain a valid SAML document from the IdP.
Exploitation of this vulnerability allows for user impersonation during SAML authentication, potentially leading to unauthorized access or actions on behalf of the impersonated user.
Users can upgrade to passport-wsfed-saml2 version 4.6.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.