Executive brief
The miniOrange SAML Service Provider module for Drupal allows organizations to configure single sign-on through external identity providers. The module contains embedded credentials that could leak information about associated services under certain circumstances, potentially exposing configuration details about the site's authentication infrastructure.
Technical details
The vulnerability involves hardcoded or insufficiently protected credentials embedded in the module code. An attacker with access to these credentials could potentially enumerate or gather information about connected identity provider services. The issue affects all versions before 3.2.0 and is resolved by upgrading to version 3.2.0 or later.
Affected products
- miniOrange SAML SSO - Service Provider <3.2.0
Timeline
- 2026-09-09: disclosed