Executive brief
The miniOrange SAML SSO Service Provider module for Drupal allows sites to authenticate users via external identity providers. The module stores sensitive SAML authentication credentials in a manner that could expose them to users or administrators with access to Drupal's configuration or database. An attacker must first gain access to the site's configuration or underlying storage to exploit this vulnerability.
Technical details
The SAML SSO Service Provider module improperly protects sensitive authentication configuration data, allowing information disclosure to accounts with configuration access. The vulnerability requires local or administrative access to configuration or database storage mechanisms. The fix is available in version 3.2.0 and later.
Affected products
- miniOrange SAML SSO - Service Provider before 3.2.0
Timeline
- 2026-09-09: disclosed