openam-jp / openam

Other
32 stars 15 forks source link

SAMLv1.x SSO process vulnerability #286

Closed ogis-song closed 10 months ago

ogis-song commented 1 year ago

Description

OpenAM does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process.

Attackers can impersonate any OpenAM user, including the administrator, by exploiting this vulnerability.

This is the same vulnerability announced as OpenIdentityPlatform/OpenAM CVE-2023-37471. https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-4mh8-9wq6-rjxg