User Impersonation Vulnerability in Auth0 Passport-WSFED-SAML2 Library
CVE-2017-16897
8.1HIGH
What is CVE-2017-16897?
A vulnerability exists in the Auth0 passport-wsfed-saml2 library that allows an attacker to impersonate legitimate users. This occurs when the SAML identity provider fails to sign the full SAML response, enabling a scenario where an unauthorized individual can gain elevated privileges by exploiting this flaw. Affected versions include those prior to 3.0.5. It is essential for users to upgrade to the latest version to mitigate this risk.
