Executive brief
passport-saml is a Node.js library that implements SAML authentication for web applications. An attacker in possession of an arbitrary IDP-signed XML element can bypass SAML authentication entirely, gaining unauthorized access to protected websites. In some configurations, this attack may require no prior valid user credentials.
Technical details
The vulnerability is a signature bypass (CWE-347) in SAML authentication libraries caused by improper XML parsing that fails to reject documents with multiple root elements. An attacker can craft a malicious SAML response containing an arbitrary IDP-signed XML element to forge authentication. The attack is network-reachable and requires no user interaction; however, the attacker must obtain or generate a valid IDP-signed XML element. Successful exploitation allows complete bypass of SAML authentication, granting unauthorized access to protected applications. Patches are available in passport-saml 3.2.2 and node-saml 4.0.0-beta.5 or later.
Affected products
- node-saml passport-saml before 3.2.2
- node-saml node-saml before 4.0.0-beta.5
- node-saml @node-saml/node-saml before 4.0.0-beta.5
- node-saml @node-saml/passport-saml before 4.0.0-beta.3
Timeline
- 2022-10-12: disclosed: Advisory published
- 2022-10-12: patched: passport-saml 3.2.2 and node-saml 4.0.0-beta.5 released