{"id":"GHSA-mfcp-34xw-p57x","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mfcp-34xw-p57x","summary":"Authentication Bypass in saml2-js","details":"Versions of `saml2-js` prior to 2.0.5 are vulnerable to an Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.\n\n\n## Recommendation\n\nUpgrade to version 2.0.5 or later.","published":"2020-09-03T21:20:52Z","modified":"2021-09-29T20:12:42Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"saml2-js","fixedVersion":"2.0.5"}],"fix":{"url":"https://github.com/Clever/saml2/pull/190","label":"Clever/saml2#190"},"references":[{"type":"WEB","url":"https://github.com/Clever/saml2/pull/190"},{"type":"WEB","url":"https://github.com/Clever/saml2/commit/ae0da4d0a0ea682a737be481e3bd78798be405c0"},{"type":"PACKAGE","url":"https://github.com/Clever/saml2"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SAML2JS-474637"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1222"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-29T20:12:42Z"}}