Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers
Vulnerability Description
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text placeholders of a SAML XML template using samlify 2.10.0, which left those placeholders unescaped. An authenticated low-privilege user could place XML markup in a profile attribute so Logto signed a forged SAML attribute, such as an arbitrary role, allowing privilege escalation at relying Service Providers that authorize on SAML attributes. This issue is fixed in version 1.41.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Vulnerability Type
XML注入(XPath盲注)
Vulnerability Title
logto-io logto 输入验证错误漏洞
Vulnerability Description
logto-io logto是logto-io组织的一个身份认证和用户管理平台。 logto-io logto 1.41.0之前版本存在输入验证错误漏洞,该漏洞源于使用samlify 2.10.0构建SAML响应时,对用户可控的个人资料属性(如名称、电子邮件和自定义属性映射值)未进行转义处理,导致经过身份验证的低权限用户可在个人资料属性中插入XML标记,从而伪造SAML属性实现权限提升。
CVSS Information
N/A
Vulnerability Type
N/A