QID 981418
QID 981418: Nodejs (npm) Security Update for passport-saml (GHSA-5379-r78w-42h2)
Security update has been released for passport-saml to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service. This would be an effective way to perform a denial-of-service attack.
Solution
This has been resolved in version 3.1.0. The resolution is to limit the number of allowable transforms to 2.
Vendor References
- GHSA-5379-r78w-42h2 -
github.com/advisories/GHSA-5379-r78w-42h2
CVEs related to QID 981418
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5379-r78w-42h2 | passport-saml |
|