QID 981233

QID 981233: Nodejs (npm) Security Update for passport-wsfed-saml2 (GHSA-7fpw-cfc4-3p2c)

A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Customers are advised to refer to GHSA-7fpw-cfc4-3p2c for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981233

    Software Advisories
    Advisory ID Software Component Link
    GHSA-7fpw-cfc4-3p2c passport-wsfed-saml2 URL Logo github.com/advisories/GHSA-7fpw-cfc4-3p2c