原始 OSV JSON{
"id": "GHSA-mfcp-34xw-p57x",
"aliases": [],
"details": "Versions of `saml2-js` prior to 2.0.5 are vulnerable to an Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.\n\n\n## Recommendation\n\nUpgrade to version 2.0.5 or later.",
"summary": "Authentication Bypass in saml2-js",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0.5"
}
]
}
],
"package": {
"name": "saml2-js",
"ecosystem": "npm"
}
}
],
"modified": "2021-09-29T20:12:42Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"published": "2020-09-03T21:20:52Z",
"references": [
{
"url": "https://github.com/Clever/saml2/pull/190",
"type": "WEB"
},
{
"url": "https://github.com/Clever/saml2/commit/ae0da4d0a0ea682a737be481e3bd78798be405c0",
"type": "WEB"
},
{
"url": "https://github.com/Clever/saml2",
"type": "PACKAGE"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-SAML2JS-474637",
"type": "WEB"
},
{
"url": "https://www.npmjs.com/advisories/1222",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-287"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2020-08-31T18:51:27Z"
}
}