PT-2022-16038 · Unknown · Passport-Wsfed-Saml2

·

CVE-2022-23505

·

Published

2022-12-13

·

Updated

2023-07-14

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Passport-wsfed-saml2 versions prior to 4.6.3
Description A remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the attacker is in possession of an arbitrary IDP signed assertion. Depending on the IDP used, fully unauthenticated attacks might also be feasible if generation of a signed message can be triggered.
Recommendations Upgrade the library to version 4.6.3. As a temporary workaround, consider using SAML2 authentication instead of WSFed until the issue is resolved.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23505
GHSA-PPJQ-QXHX-M25F

Affected Products

Passport-Wsfed-Saml2