Back

CRITICAL

Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal

Published Apr 17, 2019

Description

OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner duo
Published Apr 17, 2019
Updated Aug 5, 2024
Reserved Jul 18, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-94HM-8Q65-RMXM