tngan samlify
cpe:2.3:a:samlify_project:samlify:*:*:*:*:*:*:*
- < 2.10.0
A Signature Wrapping vulnerability has been identified in the samlify library for Node.js, specifically in versions prior to 2.10.0. This vulnerability allows an attacker to forge a SAML Response and authenticate as any user. To exploit this issue, the attacker must possess a signed XML document from the identity provider.
Exploitation of this vulnerability could lead to unauthorized user authentication by forging SAML Responses.
The vulnerability can be reproduced by using a version of samlify prior to 2.10.0. An attacker must obtain a signed XML document from the identity provider and then manipulate it to include a forged SAML Response that can be accepted by the service provider.
Users can upgrade to samlify version 2.10.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.