漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
Vulnerability Description
Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
Clever saml2-js 授权问题漏洞
Vulnerability Description
Clever saml2-js是一款使用在Clever产品中的SAML(安全断言标记语言)脚本。 Clever saml2-js 2.0版本和1.0版本中存在身份验证绕过漏洞。攻击者可利用该漏洞绕过身份验证机制并执行未授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A