{"id":"CVE-2024-25718","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-25718","summary":"In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a…","details":"In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.","published":"2024-02-11T05:15:08.463","modified":"2026-06-17T07:16:28.040","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/dropbox/samly/pull/13","label":"dropbox/samly#13"},"references":[{"type":"FIX","url":"https://diff.hex.pm/diff/samly/1.3.0..1.4.0"},{"type":"WEB","url":"https://github.com/dropbox/samly"},{"type":"FIX","url":"https://github.com/dropbox/samly/pull/13"},{"type":"FIX","url":"https://github.com/dropbox/samly/pull/13/commits/812b5c3ad076dc9c9334c1a560c8e6470607d1eb"},{"type":"WEB","url":"https://github.com/handnot2/samly"},{"type":"WEB","url":"https://hex.pm/packages/samly"},{"type":"FIX","url":"https://diff.hex.pm/diff/samly/1.3.0..1.4.0"},{"type":"WEB","url":"https://github.com/dropbox/samly"},{"type":"FIX","url":"https://github.com/dropbox/samly/pull/13"},{"type":"FIX","url":"https://github.com/dropbox/samly/pull/13/commits/812b5c3ad076dc9c9334c1a560c8e6470607d1eb"},{"type":"WEB","url":"https://github.com/handnot2/samly"},{"type":"WEB","url":"https://hex.pm/packages/samly"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T07:16:28.040"}}