15.1.3
4 years ago
2 months ago
Known vulnerabilities in the org.openidentityplatform.openam:openam-federation-library package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Improper Authentication due to not properly validating the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process. Attackers can use this fact to impersonate any OpenAM user, including the administrator, by sending a specially crafted SAML response to the How to fix Improper Authentication? Upgrade | [,14.7.3) |