cbcvebase.
CVE-2022-39299
published 2022-10-12

CVE-2022-39299: Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML…

PriorityP356high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
3.02%
86.0th percentile
Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker may be able to bypass SAML authentication on a website using passport-saml. A successful attack requires that the attacker is in possession of an arbitrary IDP signed XML element. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. Users should upgrade to passport-saml version 3.2.2 or newer. The issue was also present in the beta releases of `node-saml` before version 4.0.0-beta.5. If you cannot upgrade, disabling SAML authentication may be done as a workaround.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiannode-xmldom< node-xmldom 0.8.6-1 (bookworm)node-xmldom 0.8.6-1 (bookworm)
node-samlnode-saml>= 0 < 4.0.0-beta.54.0.0-beta.5
node-samlpassport-saml>= 0 < 4.0.0-beta.34.0.0-beta.3
passport-saml_projectpassport-saml< 3.2.23.2.2
passport-saml_projectpassport-saml
passport-saml_projectpassport-saml>= 0 < 3.2.23.2.2
xmldomxmldom< 0.7.70.7.7
xmldomxmldom<= 0.6.0
xmldomxmldom
xmldomxmldom
xmldomxmldom>= 0 < 0.7.70.7.7
xmldomxmldom0 – 0.6.0
xmldomxmldom>= 0.8.0 < 0.8.40.8.4
xmldomxmldom>= 0.9.0-beta.1 < 0.9.0-beta.40.9.0-beta.4
xmldom_projectxmldom< 0.6.00.6.0
xmldom_projectxmldom
xmldom_projectxmldom>= 0.7.0 < 0.7.70.7.7
xmldom_projectxmldom>= 0.8.0 < 0.8.40.8.4

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.