In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade passport-wsfed-saml2
to version 3.0.10 or higher.
passport-wsfed-saml2 is a SAML2 Protocol and WS-Fed library.
Affected versions of this package are vulnerable to Improper Control of Document Type Definition due to improper validation of a SAML signature tag, which leads to a signature relocation attack where the attacker can corrupt one field of data while maintaining the signature valid. This could allow an authenticated attacker to "remove" one group from the assertion or corrupt another field.