库版本 0.1.13 及之前版本中,SAML 签名验证依赖于一个可选的 选项,这使得攻击者可以通过提交未经签名的 SAML 响应来绕过身份验证。攻击者可以向断言消费端点(assertion consumer service endpoint)提交伪造的 SAML 响应(包含任意的 和属性),从而在没有有效签名的情况下获取已认证的档案信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| krakenjs | passport-saml-encrypted | 0 ~ 0.1.13 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet