auth0/passport-wsfed-saml2
cpe:2.3:a:auth0:passport-wsfed-saml2:*:*:*:*:*:*:*
- >= 3.0.5, <= 4.6.3
A vulnerability in passport-wsfed-saml2, present in versions 3.0.5 prior to 4.6.3, allows attackers to impersonate users during SAML authentication by modifying a valid SAML response. This exploitation involves adding attributes to the response. Users are specifically affected when their service provider utilizes passport-wsfed-saml2 and a valid, signed SAML response from the Identity Provider is accessible.
Exploitation of this vulnerability allows for unauthorized user impersonation during SAML authentication, potentially leading to unauthorized access or actions on behalf of the impersonated user.
Users can upgrade to version 4.6.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.