saml2-js is a node module that abstracts away the complexities of the SAML protocol behind an easy to use interface.
Affected versions of this package are vulnerable to Authentication Bypass. The package fails to enforce the assertion conditions for encrypted assertions, which may allow an attacker to reuse encrypted assertion tokens indefinitely.
saml2-js to version 2.0.5 or higher.
- Jon Langlois
- Snyk ID
- 21 Oct, 2019
- 01 Nov, 2019