Executive brief
Samlify is a library for handling SAML (Security Assertion Markup Language) authentication, commonly used by web applications to enable single sign-on. Versions before 2.4.0-rc5 contain a flaw that allows attackers to reuse SAML tokens with different usernames by wrapping XML signatures in a way that bypasses validation, potentially allowing unauthorized users to access systems using forged credentials.
Technical details
The vulnerability is an XML Signature Wrapping attack (CWE-347, CWE-91) in Samlify's SAML token validation logic. The library fails to properly prevent signature wrapping, allowing an attacker to modify SAML content (such as the username/NameID) while preserving the cryptographic signature's validity. This occurs because the signature validation does not detect structural manipulation of the XML document. The attack is network-reachable and requires no authentication or user interaction. A remote attacker can craft a malicious SAML response and use it to impersonate any user in the system. The fix, released in version 2.4.0-rc5, adds stricter signature validation and wrapping attack detection.
Affected products
- Samlify samlify prior to 2.4.0-rc5
Timeline
- 2018-01-04: disclosed
- 2018-09-28: patched: Fix committed to repository