OSV 1.4.0 · github-reviewed · 修改于 2026-06-27 05:05
发布时间
2026-06-27 05:05
GitHub 审查时间
2026-06-27 05:05
NVD 发布时间
2026-06-19 05:16
源文件
advisories/github-reviewed/2026/06/GHSA-jv46-xfwm-36j7/GHSA-jv46-xfwm-36j7.json
Relyra 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result.
In 1.0.0 and 1.1.0, the XMLDSig trust boundary was incomplete. :public_key.verify over the exclusive-C14N canonicalized SignedInfo was not performed against the configured IdP certificate's public key, DigestValue was not recomputed over the canonicalized referenced element, and canonicalize/2 remained an unused passthrough in the signature-verification path. The result was a structure-only acceptance path where document shape and trust-source rejection could succeed without proving the signature bytes.
A forged SignatureValue carrying an attacker-controlled NameID can be accepted as {:ok}. Any relying-party application using Relyra 1.0.0 or 1.1.0 can be logged into as an arbitrary user if it trusts the affected response path.
Relyra 1.2.0 closes the gap with real exclusive-C14N canonicalization, :public_key.verify against the configured IdP certificate's public key, and a constant-time DigestValue recompute/compare bound to the exact consumed node on both verify/4 and verify_metadata_root/4.
There is no safe configuration of 1.0.0 or 1.1.0. Upgrade to 1.2.0 or later.
2e45689 (wire real XMLDSig crypto into the candidate arm)8910200 (close metadata trust bypass, pin over DER)test/security/xml/adversarial_crypto_test.exs, test/relyra/metadata/auto_refresh_test.exs, test/security/ci_gate_integrity_test.exs