org.springframework.security:spring-security-saml2-service-provider@5.3.11.RELEASE

  • latest version

    7.1.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.springframework.security:spring-security-saml2-service-provider package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Handling of Highly Compressed Data (Data Amplification)

    org.springframework.security:spring-security-saml2-service-provider is a security component for the Spring Framework.

    Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) in the REDIRECT binding. An attacker can exhaust system memory by submitting a specially crafted compressed SAML payload that, when inflated, consumes excessive resources.

    How to fix Improper Handling of Highly Compressed Data (Data Amplification)?

    Upgrade org.springframework.security:spring-security-saml2-service-provider to version 6.5.11, 7.0.6 or higher.

    [,6.5.11)[7.0.0-M1,7.0.6)
    • M
    Cross-site Scripting (XSS)

    org.springframework.security:spring-security-saml2-service-provider is a security component for the Spring Framework.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the RelyingPartyRegistration function. An attacker can execute arbitrary scripts in the context of the user's browser by injecting malicious values into HTML forms generated by security filters.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.springframework.security:spring-security-saml2-service-provider to version 6.5.11, 7.0.6 or higher.

    [,6.5.11)[7.0.0-M1,7.0.6)
    • M
    Information Exposure

    org.springframework.security:spring-security-saml2-service-provider is a security component for the Spring Framework.

    Affected versions of this package are vulnerable to Information Exposure via SAML message decryption prior to signature validation. An attacker can use the Service Provider as a decryption oracle by submitting crafted encrypted SAML Responses, LogoutRequests, or LogoutResponses that are processed before a valid signature is verified. This may allow an attacker to gain information about encrypted data through repeated interactions with the SAML processing workflow.

    How to fix Information Exposure?

    Upgrade org.springframework.security:spring-security-saml2-service-provider to version 6.5.11, 7.0.6 or higher.

    [,6.5.11)[7.0.0-M1,7.0.6)