CVE-2022-39300
HIGHnode-saml < 4.0.0 - Improper Verification of Cryptographic Signature
Title source: llmDescription
node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to node-saml version 4.0.0-beta5 or newer. Disabling SAML authentication may be done as a workaround.
References (2)
Core 2
Core References
Patch, Third Party Advisory
https://github.com/node-saml/node-saml/commit/c1f275c289c01921e58f5c70ce0fdbc5287e5fbe
Third Party Advisory
https://github.com/node-saml/node-saml/security/advisories/GHSA-5p8w-2mvw-38pv
Scores
CVSS v3
7.7
EPSS
0.0015
EPSS Percentile
35.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-347
Status
published
Products (3)
node_saml_project/node_saml
4.0.0 beta0 (5 CPE variants)
node_saml_project/node_saml
< 4.0.0
npm/node-saml
0 - 4.0.0-beta.5npm
Published
Oct 13, 2022
Tracked Since
Feb 18, 2026