CVE-2022-39300

HIGH

node-saml < 4.0.0 - Improper Verification of Cryptographic Signature

Title source: llm
STIX 2.1

Description

node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to node-saml version 4.0.0-beta5 or newer. Disabling SAML authentication may be done as a workaround.

Scores

CVSS v3 7.7
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (3)
node_saml_project/node_saml 4.0.0 beta0 (5 CPE variants)
node_saml_project/node_saml < 4.0.0
npm/node-saml 0 - 4.0.0-beta.5npm
Published Oct 13, 2022
Tracked Since Feb 18, 2026