Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Vulnerability Description
Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result. The XMLDSig trust boundary was incomplete as :public_key.verify over the exclusive-C14N canonicalized SignedInfo was not performed against the configured IdP certificate's public key, DigestValue was not recomputed over the canonicalized referenced element, and canonicalize/2 remained an unused passthrough in the signature-verification path. The result was a structure-only acceptance path where document shape and trust-source rejection could succeed without proving the signature bytes. A forged SignatureValue carrying an attacker-controlled NameID could be accepted as {:ok}. This issue has been fixed in version 1.2.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
szTheory relyra 授权问题漏洞
Vulnerability Description
szTheory relyra是szTheory个人开发者的一款服务器软件与网络产品。 szTheory relyra 1.0.0版本和1.1.0版本存在安全漏洞,该漏洞源于XMLDSig信任边界不完整,未对SignatureValue进行加密验证,导致接受伪造SAML签名,可能导致攻击者控制NameID。
CVSS Information
N/A
Vulnerability Type
N/A