cbcvebase.
CVE-2020-27846
published 2020-12-21

CVE-2020-27846: A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.87%
91.1th percentile
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Affected

12 ranges
VendorProductVersion rangeFixed in
crewjamsaml
fedoraprojectfedora
fedoraprojectfedora
github.comcrewjam_saml>= 0 < 0.4.30.4.3
grafanagrafana< 6.7.56.7.5
grafanagrafana>= 7.0.0 < 7.2.37.2.3
grafanagrafana>= 7.3.0 < 7.3.67.3.6
redhatenterprise_linux
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_service_mesh
saml_projectsaml< 0.4.30.4.3

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is a SAML signature verification bypass in the crewjam/saml Go module; detect exploitation by monitoring for SAML authentication successes that lack a valid cryptographic signature, particularly where XML namespace prefix or attribute/directive round-trip instability may be exploited.
  • Applications using Go's encoding/xml package for SAML or XML-DSig processing are at risk due to XML tokenization round-trip instability (attribute, directive, and element namespace prefix semantics); audit all SAML-processing code paths that rely on crewjam/saml for signature validation integrity.
  • Workaround/detection aid: use Mattermost's xml-roundtrip-validator to validate XML round-trip stability before processing SAML assertions, which can help detect crafted malicious inputs exploiting this class of vulnerability.
  • ·Grafana deployments using oauth-proxy as an Auth Proxy do NOT use the vulnerable SAML authentication path in crewjam/saml and are not exploitable via this CVE.
  • ·SAML is only available in the Enterprise version of Grafana; non-Enterprise deployments packaging crewjam/saml are not exploitable even if the vulnerable code is present.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.