pac4j-saml 在 6.5.6 之前的版本中,未在 中强制校验 SAML LogoutRequest 消息的签名。当身份提供者(IdP)未发送 SessionIndex 时,仅凭 NameID 即可销毁会话。这使得未认证的 attackers 能够提交一个未签名的 LogoutRequest,并使用猜测的标识符(例如用作 NameID 的电子邮件地址)来终止受害者的 SAML 会话。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82463 | 8.1 HIGH | pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check |
| CVE-2026-82461 | 8.1 HIGH | pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token |
| CVE-2026-82462 | 6.5 MEDIUM | pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution |
| CVE-2026-82464 | 6.1 MEDIUM | pac4j-core before 6.5.6 Open Redirect via Backslash Logout |
No comments yet