漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
Vulnerability Description
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profile attribute so Logto signed a forged SAML attribute, such as an arbitrary role, allowing privilege escalation at relying Service Providers that authorize on SAML attributes. This issue is fixed in version 1.41.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Vulnerability Type
XML注入(XPath盲注)
Vulnerability Title
logto-io logto 输入验证错误漏洞
Vulnerability Description
logto-io logto是logto-io组织的一个身份认证和用户管理平台。 logto-io logto 1.41.0之前版本存在输入验证错误漏洞,该漏洞源于使用samlify 2.10.0构建SAML响应时,对用户可控的个人资料属性(如名称、电子邮件和自定义属性映射值)未进行转义处理,导致经过身份验证的低权限用户可在个人资料属性中插入XML标记,从而伪造SAML属性实现权限提升。
CVSS Information
N/A
Vulnerability Type
N/A