OneLogin SAML SSO < 2.2.0 - Authentication Bypass

2016-01-21 00:00
Jouko Pynnöne

Strategic Overview

Status
Patched in 2.2.0
Affected PluginOneLogin SAML SSO
Affected Version< 2.2.0
CVSS7.5High
CVECVE-2016-10928
View all OneLogin SAML SSO vulnerabilities

Vulnerability Overview

The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

Technical Analysis

REMEDIATION: Update to version 2.2.0, or a newer patched version --- IDENTIFIER: CWE-798 (Use of Hard-coded Credentials) The product contains hard-coded credentials, such as a password or cryptographic key.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C