QID 995308
Date Published: 2023-09-25
QID 995308: DotNet (Nuget) Security Update for Sustainsys.Saml2 (GHSA-fv2h-753j-9g39)
When a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fv2h-753j-9g39 for updates and patch information.
Vendor References
- GHSA-fv2h-753j-9g39 -
github.com/advisories/GHSA-fv2h-753j-9g39
CVEs related to QID 995308
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fv2h-753j-9g39 | Sustainsys.Saml2 |
|