7.1.0
6 years ago
2 months ago
Known vulnerabilities in the org.springframework.security:spring-security-saml2-service-provider package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.springframework.security:spring-security-saml2-service-provider is a security component for the Spring Framework. Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) in the How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade | [,6.5.11)[7.0.0-M1,7.0.6) |
org.springframework.security:spring-security-saml2-service-provider is a security component for the Spring Framework. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,6.5.11)[7.0.0-M1,7.0.6) |
org.springframework.security:spring-security-saml2-service-provider is a security component for the Spring Framework. Affected versions of this package are vulnerable to Information Exposure via SAML message decryption prior to signature validation. An attacker can use the Service Provider as a decryption oracle by submitting crafted encrypted SAML Responses, LogoutRequests, or LogoutResponses that are processed before a valid signature is verified. This may allow an attacker to gain information about encrypted data through repeated interactions with the SAML processing workflow. How to fix Information Exposure? Upgrade | [,6.5.11)[7.0.0-M1,7.0.6) |