Improper Control of Document Type Definition Affecting passport-wsfed-saml2 package, versions <3.0.10


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-PASSPORTWSFEDSAML2-5730770
  • published22 Jun 2023
  • disclosed21 Jun 2023
  • creditUnknown

Introduced: 21 Jun 2023

CVE NOT AVAILABLE CWE-827  (opens in a new tab)

How to fix?

Upgrade passport-wsfed-saml2 to version 3.0.10 or higher.

Overview

passport-wsfed-saml2 is a SAML2 Protocol and WS-Fed library.

Affected versions of this package are vulnerable to Improper Control of Document Type Definition due to improper validation of a SAML signature tag, which leads to a signature relocation attack where the attacker can corrupt one field of data while maintaining the signature valid. This could allow an authenticated attacker to "remove" one group from the assertion or corrupt another field.

CVSS Scores

version 3.1