Junglewise Threat Intelligence

CVE-2017-1000452: Samlify authentication bypass via XML signature wrapping

CVE-2017-1000452 · Severity: low · CVSS 3 · Published 2018-01-04

Technologies: samlify (npm). Vendors: npm.

Executive brief

Samlify is a library for handling SAML (Security Assertion Markup Language) authentication, commonly used by web applications to enable single sign-on. Versions before 2.4.0-rc5 contain a flaw that allows attackers to reuse SAML tokens with different usernames by wrapping XML signatures in a way that bypasses validation, potentially allowing unauthorized users to access systems using forged credentials.

Technical details

The vulnerability is an XML Signature Wrapping attack (CWE-347, CWE-91) in Samlify's SAML token validation logic. The library fails to properly prevent signature wrapping, allowing an attacker to modify SAML content (such as the username/NameID) while preserving the cryptographic signature's validity. This occurs because the signature validation does not detect structural manipulation of the XML document. The attack is network-reachable and requires no authentication or user interaction. A remote attacker can craft a malicious SAML response and use it to impersonate any user in the system. The fix, released in version 2.4.0-rc5, adds stricter signature validation and wrapping attack detection.

Affected products

  • Samlify samlify prior to 2.4.0-rc5

Timeline

  • 2018-01-04: disclosed
  • 2018-09-28: patched: Fix committed to repository

References

Related threats