CVE-2020-5407

HIGH

Spring Security 5.2.0-5.2.3 and 5.3.0-5.3.1 - SAML Signature Wrapping via Assertion Injection

Title source: llm
STIX 2.1

Description

Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion that Spring Security will accept as valid.

Scores

CVSS v3 8.8
EPSS 0.0120
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (2)
org.springframework.security/spring-security-core 5.2.0 - 5.2.4Maven
pivotal_software/spring_security 5.2.0 - 5.2.4
Published May 13, 2020
Tracked Since Feb 18, 2026