Junglewise Threat Intelligence

Auth0 passport-wsfed-saml2 authentication bypass

Severity: low · CVSS 3 · Published 2017-12-28

Technologies: passport-wsfed-saml2 (npm). Vendors: Auth0, npm.

Executive brief

The Auth0 passport-wsfed-saml2 library is used for SAML-based authentication in web applications. A vulnerability allows an attacker to impersonate other users and escalate privileges by forging SAML responses when the identity provider fails to sign the complete response. This could enable account takeover and unauthorized access to protected resources.

Technical details

The vulnerability (CWE-290: Improper Validation of Cryptographic Signature) occurs in passport-wsfed-saml2 versions before 3.0.5 when processing SAML responses that are not fully signed by the identity provider. An attacker can forge or modify SAML assertions, including only-asserted-signed responses, to impersonate legitimate users without valid credentials. The attack requires no authentication or user interaction and is network-accessible. The fix is available in version 3.0.5 and later.

Affected products

  • Auth0 passport-wsfed-saml2 < 3.0.5

Timeline

  • 2017-12-28: disclosed
  • 2023-06-21: other: Advisory withdrawn as duplicate of GHSA-77fw-rf4v-vfp9

References

Related threats