Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FusionAuth fusionauth-samlv2 数据伪造问题漏洞
Vulnerability Description
fusionauth fusionauth-samlv2是个人开发者的一个提供JAXB功能的JAVA库。该库主要可以处理SAML请求和回复,用于单点登录等场景。 FusionAuth fusionauth-samlv2 0.2.3 存在安全漏洞,攻击者可利用该漏洞伪造消息和绕过身份验证通过SAML断言,缺乏标志性元素,又名“签名排除攻击”。
CVSS Information
N/A
Vulnerability Type
N/A