漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CVE-2026-9095
Vulnerability Description
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcement, or replay detection anywhere in the SAML SP code path. As a result, an attacker can replay a previously captured SAML assertion to obtain an authenticated session for the assertion’s subject, including administrator accounts, without needing the user’s password or MFA credentials.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Casdoor 安全漏洞
Vulnerability Description
Casdoor是Casdoor开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor 2.362.0及之前版本存在安全漏洞,该漏洞源于将SAML断言映射到用户会话时缺乏重放保护,因为object/saml_sp.go中的ParseSamlResponse函数调用sp.RetrieveAssertionInfo并立即将结果映射到用户会话,SAML SP代码路径中没有任何断言ID缓存、OneTimeUse条件执行或重放检测,攻击者可以重放先前捕获的SAML断言来获取断言主题的身份验证会话,包括管理员
CVSS Information
N/A
Vulnerability Type
N/A