Executive brief
Passport-wsfed-saml2 is a Node.js library used to add SAML-based single sign-on (SSO) authentication to web applications. An attacker who obtains a valid SAML response from an identity provider can manipulate it by adding extra attributes, allowing them to impersonate any user and bypass authentication controls. This could lead to unauthorized access to sensitive user accounts and data.
Technical details
This vulnerability is a SAML authentication bypass resulting from improper attribute validation (CWE-287, CWE-290). The root cause is insufficient sanitization of SAML response attributes; an attacker can inject or modify attributes in a validly-signed SAML assertion to impersonate arbitrary users. The attack requires a valid SAML response signed by the identity provider, but no additional authentication or user interaction is needed once this response is obtained. An attacker can achieve full user impersonation and account takeover. The fix is available in version 4.6.4 and later.
Affected products
- Auth0 passport-wsfed-saml2 3.0.5 to 4.6.3
Timeline
- 2025-05-06: disclosed
- 2025-05-06: patched: v4.6.4 and later