漏洞描述:数据真实性验证不足 Dropbox 中使用的 Samly 组件存在“数据真实性验证不足”漏洞,攻击者可以利用服务提供方(Service Provider, SP)从未请求过的 SAML 响应,建立已认证的会话。 在 Samly 中, 函数(位于 )在服务提供方发起的流程中验证 SAML 响应时,仅比对了 值、身份提供方(IdP)标识符以及会话中保存的目标 URL。该函数从未将 与 SP 发出的 的 ID 进行比较,而且该请求 ID 也从未被持久化存储,因此根本不可能进行比对。 根据 SAML 2.0 规范
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dropbox | samly | 0.3.0 ~ * |
cpe:2.3:a:dropbox:samly:*:*:*:*:*:*:*:*
|
|
| dropbox | samly | 8a5bb1b4a4753d05470da2036323477f63cfdf4c ~ * |
cpe:2.3:a:dropbox:samly:*:*:*:*:*:*:*:*
|
|
| handnot2 | samly | 8a5bb1b4a4753d05470da2036323477f63cfdf4c ~ * |
cpe:2.3:a:handnot2:samly:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet