Junglewise Threat Intelligence

CVE-2022-39299: passport-saml signature bypass via multiple root elements

CVE-2022-39299 · Severity: low · CVSS 3.1 · Published 2022-10-12

Technologies: @node-saml/node-saml (npm), passport-saml (npm), Node-Saml. Vendors: npm.

Executive brief

passport-saml is a Node.js library that implements SAML authentication for web applications. An attacker in possession of an arbitrary IDP-signed XML element can bypass SAML authentication entirely, gaining unauthorized access to protected websites. In some configurations, this attack may require no prior valid user credentials.

Technical details

The vulnerability is a signature bypass (CWE-347) in SAML authentication libraries caused by improper XML parsing that fails to reject documents with multiple root elements. An attacker can craft a malicious SAML response containing an arbitrary IDP-signed XML element to forge authentication. The attack is network-reachable and requires no user interaction; however, the attacker must obtain or generate a valid IDP-signed XML element. Successful exploitation allows complete bypass of SAML authentication, granting unauthorized access to protected applications. Patches are available in passport-saml 3.2.2 and node-saml 4.0.0-beta.5 or later.

Affected products

  • node-saml passport-saml before 3.2.2
  • node-saml node-saml before 4.0.0-beta.5
  • node-saml @node-saml/node-saml before 4.0.0-beta.5
  • node-saml @node-saml/passport-saml before 4.0.0-beta.3

Timeline

  • 2022-10-12: disclosed: Advisory published
  • 2022-10-12: patched: passport-saml 3.2.2 and node-saml 4.0.0-beta.5 released

References

Related threats