Casdoor
cpe:2.3:a:casbin:casdoor:*:*:*:*:*:*:*
- <= 2.362.0
An authentication bypass vulnerability has been identified in Casdoor versions through 2.362.0. This issue arises because the buildSpCertificateStore function extracts X.509 certificates directly from incoming SAML responses, rather than using a trusted, pre-configured Identity Provider certificate. As a result, attackers can supply their own signing certificates to forge assertions, bypassing authentication controls.
Exploitation of this vulnerability allows attackers to impersonate users by forging SAML assertions, including those of administrators, and bypass authentication requirements such as multi-factor authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.