Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-11430
HistoryApr 17, 2019 - 2:29 p.m.

Authentication flaw

2019-04-1714:29:00
PRIOn knowledge base
www.prio-n.com
2

9.4 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%

OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

CPENameOperatorVersion
omnitauth-samlle1.9.0

9.4 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.2%