Show filters
22 Total Results
Displaying 21-22 of 22
Sort by:
Attacker Value
Unknown
CVE-2017-16897
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).
0
Attacker Value
Unknown
CVE-2016-7191
Disclosure Date: September 28, 2016 (last updated November 25, 2024)
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote attackers to bypass authentication via a crafted token.
0