WrenSecurity / wrenam

Community fork of OpenAM, an authentication and authorization system originally developed by ForgeRock.
Other
43 stars 27 forks source link

[CVE-2021-37154] Escape SAML request inResponseTo attribute. #130

Closed karelmaxa closed 1 year ago

karelmaxa commented 1 year ago

This PR introduces XML escaping of the SAML response attribute inResponseTo to resolve the security vulnerability published as a CVE-2021-37154.

I was able to reproduce the exploit using the current version built with JDK 17.