CVE-2023-45683
published 2023-10-16CVE-2023-45683: github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.43%
35.2th percentile
github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider. Note: SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permissions or publicly accessible to ease the IdP interoperability. This issue is fixed in version 0.4.14. Users unable to upgrade may perform external validation of URLs provided in SAML metadata, or restrict the ability for end-users to upload arbitrary metadata.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| crewjam | saml | < 0.4.14 | 0.4.14 |
| github.com | crewjam_saml | >= 0 < 0.4.14 | 0.4.14 |
| saml_project | saml | < 0.4.14 | 0.4.14 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml
osv·2023-10-24
CVE-2023-45683 Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml
Cross-site scripting via missing binding syntax validation in github.com/crewjam/saml
The package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim's browser loads the SAML IdP initiated SSO link for the malicious service provider.
OSV
Cross-site Scripting via missing Binding syntax validation
osv·2023-10-17
CVE-2023-45683 [HIGH] Cross-site Scripting via missing Binding syntax validation
Cross-site Scripting via missing Binding syntax validation
### Impact
The package does not validate the ACS Location URI according to the SAML binding being parsed.
If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow.
Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider.
Note: The severity is considered “High” because the SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permissions or publicly accessible to ease the IdP in
GHSA
Cross-site Scripting via missing Binding syntax validation
ghsa·2023-10-17
CVE-2023-45683 [HIGH] CWE-79 Cross-site Scripting via missing Binding syntax validation
Cross-site Scripting via missing Binding syntax validation
### Impact
The package does not validate the ACS Location URI according to the SAML binding being parsed.
If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow.
Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider.
Note: The severity is considered “High” because the SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permissions or publicly accessible to ease the IdP in
OSV
CVE-2023-45683: github
osv·2023-10-16·CVSS 6.1
CVE-2023-45683 [MEDIUM] CVE-2023-45683: github
github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider. Note: SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permissions or publicly accessible to ease the IdP interoperability. This issue is fixed i
Red Hat
github.com/crewjam/saml: Cross-Site-Scripting (XSS) in github.com/crewjam/saml
vendor_redhat·2023-10-16·CVSS 7.1
CVE-2023-45683 [HIGH] CWE-79 github.com/crewjam/saml: Cross-Site-Scripting (XSS) in github.com/crewjam/saml
github.com/crewjam/saml: Cross-Site-Scripting (XSS) in github.com/crewjam/saml
github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject Javascript in the ACS endpoint definition, achieving Cross-Site-Scripting (XSS) in the IdP context during the redirection at the end of a SAML SSO Flow. Consequently, an attacker may perform any authenticated action as the victim once the victim’s browser loaded the SAML IdP initiated SSO link for the malicious service provider. Note: SP registration is commonly an unrestricted operation in IdPs, hence not requiring particular permission
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/crewjam/saml/commit/b07b16cf83c4171d16da4d85608cb827f183cd79https://github.com/crewjam/saml/security/advisories/GHSA-267v-3v32-g6q5https://github.com/crewjam/saml/commit/b07b16cf83c4171d16da4d85608cb827f183cd79https://github.com/crewjam/saml/security/advisories/GHSA-267v-3v32-g6q5
2023-10-16
Published