OneLogin SAML SSO <= 2.4.2 - Use of Vulnerable Component
2016-10-14 00:00
Sixto MartinStrategic Overview
Vulnerability Overview
The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.
Technical Analysis
REMEDIATION: Update to version 2.4.3, or a newer patched version --- IDENTIFIER: CWE-347 (Improper Verification of Cryptographic Signature) The product does not verify, or incorrectly verifies, the cryptographic signature for data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C