krakenjs / passport-saml-encrypted

A strategy for Passport authentication that supports encrypted SAML responses
MIT License
14 stars 26 forks source link

Update xml-encryption due to ejs vulnerability #24

Closed jerrywithaz closed 3 years ago

jerrywithaz commented 3 years ago

Update xml-encryption due to ejs vulnerability via remote code execution: https://securitylab.github.com/advisories/GHSL-2021-021-tj-ejs/

jerrywithaz commented 3 years ago

@grawk should we merge this?

kumarrishav commented 3 years ago

should we cover this as well? https://github.com/krakenjs/passport-saml-encrypted/security/dependabot