Dropbox Samly 中存在通过重放捕获数据绕过身份验证的漏洞,攻击者可以通过重新提交捕获到的 SAML 断言,以该断言所指代的主体身份完成身份验证。 Samly.Helper.decode_idp_auth_resp/3(位于 lib/samly/helper.ex)会调用 esaml_sp:validate_assertion/2。该函数的默认重复检测器是一个空操作(no-op)。虽然 esaml 中提供了接受 DuplicateFun 参数的 /3 元数版本,并实现了相应的重复检查逻辑,但 Samly
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dropbox | samly | 0.3.0 ~ * |
cpe:2.3:a:dropbox:samly:*:*:*:*:*:*:*:*
|
|
| dropbox | samly | 8a5bb1b4a4753d05470da2036323477f63cfdf4c ~ * |
cpe:2.3:a:dropbox:samly:*:*:*:*:*:*:*:*
|
|
| handnot2 | samly | 8a5bb1b4a4753d05470da2036323477f63cfdf4c ~ * |
cpe:2.3:a:handnot2:samly:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet