Executive brief
This module provides a solution to authenticate visitors using existing SAML providers.
Certain non-default configurations allow a malicious user to login as any chosen user.
The vulnerability is mitigated by the module's default settings which require the options "Either sign SAML assertions" and "x509 certificate".
Affected products
- packagist:https://packages.drupal.org/8 drupal/miniorange_saml