CVE-2022-41912
published 2022-11-28CVE-2022-41912: The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.18%
80.3th percentile
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| crewjam | saml | < 0.4.9 | 0.4.9 |
| github.com | crewjam_saml | >= 0 < 0.4.9 | 0.4.9 |
| saml_project | saml | < 0.4.9 | 0.4.9 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authentication bypass in github.com/crewjam/saml
osv·2022-11-29
CVE-2022-41912 Authentication bypass in github.com/crewjam/saml
Authentication bypass in github.com/crewjam/saml
Authentication bypass is possible when processing SAML responses containing multiple Assertion elements.
GHSA
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
ghsa·2022-11-29
CVE-2022-41912 [CRITICAL] CWE-287 crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
### Impact
The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.
### Patches
This issue has been corrected in version 0.4.9.
### Credit
This issue was reported by Felix Wilhelm from Google Project Zero.
OSV
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
osv·2022-11-29
CVE-2022-41912 [CRITICAL] crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
crewjam/saml vulnerable to signature bypass via multiple Assertion elements due to improper authentication
### Impact
The crewjam/saml go library is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements.
### Patches
This issue has been corrected in version 0.4.9.
### Credit
This issue was reported by Felix Wilhelm from Google Project Zero.
OSV
CVE-2022-41912: The crewjam/saml go library prior to version 0
osv·2022-11-28·CVSS 9.8
CVE-2022-41912 [CRITICAL] CVE-2022-41912: The crewjam/saml go library prior to version 0
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
Red Hat
crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements
vendor_redhat·2022-11-28·CVSS 9.1
CVE-2022-41912 [CRITICAL] CWE-347 crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements
crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
An authentication bypass flaw was discovered in the crewjam/saml go package. A remote unauthenticated attacker could trigger it by sending a SAML request. This would allow an escalation of privileges and then enable compromising system integrity.
Statement: Whilst the Red Hat Advanced Cluster Management for Kubernetes (RHACM) acm-grafana container include the vulnerable underscore library, the access to it is
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/170356/crewjam-saml-Signature-Bypass.htmlhttps://github.com/crewjam/saml/commit/aee3fb1edeeaf1088fcb458727e0fd863d277f8bhttps://github.com/crewjam/saml/security/advisories/GHSA-j2jp-wvqg-wc2ghttp://packetstormsecurity.com/files/170356/crewjam-saml-Signature-Bypass.htmlhttps://github.com/crewjam/saml/commit/aee3fb1edeeaf1088fcb458727e0fd863d277f8bhttps://github.com/crewjam/saml/security/advisories/GHSA-j2jp-wvqg-wc2g
2022-11-28
Published