Junglewise Threat Intelligence

DRUPAL-CONTRIB-2021-036 - This module provides a solution to authenticate visitors using existing SAML providers. Certain non-default configurations allow a maliciou

Severity: info · Published 2021-09-22

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Miniorange Saml. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module provides a solution to authenticate visitors using existing SAML providers.

Certain non-default configurations allow a malicious user to login as any chosen user.

The vulnerability is mitigated by the module's default settings which require the options "Either sign SAML assertions" and "x509 certificate".

Affected products

  • packagist:https://packages.drupal.org/8 drupal/miniorange_saml

Related threats