Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Samly 安全漏洞
Vulnerability Description
Samly是用于通过 SAML 启用 Plug/Phoenix 应用程序。 Samly 1.4.0之前版本存在安全漏洞,该漏洞源于可以返回过期的会话,这会干扰访问控制。
CVSS Information
N/A
Vulnerability Type
N/A