PT-2026-79073 · Samly · Samly
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
dropbox samly versions 0.3.0 and later
Description
An issue exists where the service provider fails to properly verify the authenticity of SAML responses. Specifically, the
validate authresp/3 function in lib/samly/sp handler.ex does not compare the SubjectConfirmationData/@InResponseTo attribute against the ID of the AuthnRequest issued by the service provider. Because the request ID is not persisted, the system cannot verify if the response corresponds to a request it actually made, which violates SAML 2.0 Core requirements. An attacker with a validly signed assertion from a trusted Identity Provider (IdP) for their own account and a RelayState matching the victim's session can establish an authenticated session using a response the service provider never requested.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samly