Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5869
HistoryMar 01, 2018 - 6:24 a.m.

Authorization Bypass

2018-03-0106:24:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3

0.011 Low

EPSS

Percentile

84.1%

saml2-js is vulnerable to authentication bypass. The application does not properly parse comments in certain XML nodes, causing text after a comment being lost before signing the SAML Message. This allows a malicious user to modify a SAML message without invalidating the cryptographic signature and bypass authentication for the SAML provider.

CPENameOperatorVersion
saml2-jsle2.0.1

0.011 Low

EPSS

Percentile

84.1%