Tag: SSO flaw

Critical Samlify SSO flaw lets attackers log in as admin
News

Critical Samlify SSO flaw lets attackers log in as admin

By inserting unsigned harmful assertions within validly signed SAML responses, a serious vulnerability in Samlify authentication bypass has been found that enables attackers to pose as admin users. A high-level authentication library called Samlify assists programmers in incorporating Single Log-Out (SLO) and SAML SSO into Node.js applications. It is a widely used tool for establishing or establishing connections with service providers (SPs) and identity providers (IdPs) via SAML. The library is used in federated identity management scenarios, by SaaS platforms, by companies installing SSO for internal tools, and by developers interfacing with corporate identity providers such as Okta or Azure AD. It has received over 200,000 downloads each week on npm, indicating its high level of ...