{"id":"CVE-2024-25718","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-25718","summary":"Samly access control vulnerability","details":"In the Samly package before 1.4.0 for Elixir, `Samly.State.Store.get_assertion/3` can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.","published":"2024-02-11T06:30:27Z","modified":"2026-09-10T03:50:06.219469377Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Hex","name":"Samly","fixedVersion":"1.4.0"}],"fix":{"url":"https://github.com/dropbox/samly/pull/13","label":"dropbox/samly#13"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-25718"},{"type":"WEB","url":"https://github.com/dropbox/samly/pull/13"},{"type":"WEB","url":"https://github.com/dropbox/samly/pull/13/commits/812b5c3ad076dc9c9334c1a560c8e6470607d1eb"},{"type":"WEB","url":"https://github.com/dropbox/samly/commit/7637ebeef6c6b88ec2032f5323c32edcebbacbc6"},{"type":"WEB","url":"https://diff.hex.pm/diff/samly/1.3.0..1.4.0"},{"type":"PACKAGE","url":"https://github.com/dropbox/samly"},{"type":"WEB","url":"https://github.com/handnot2/samly"},{"type":"WEB","url":"https://hex.pm/packages/samly"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:06.219469377Z"}}