OneLogin SAML SSO <= 2.4.2 - Use of Vulnerable Component

2016-10-14 00:00
Sixto Martin

Strategic Overview

Status
Patched in 2.4.3
Affected PluginOneLogin SAML SSO
Affected Version<= 2.4.2
CVSS7.3High
CVEN/A
View all OneLogin SAML SSO vulnerabilities

Vulnerability Overview

The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.

Technical Analysis

REMEDIATION: Update to version 2.4.3, or a newer patched version --- IDENTIFIER: CWE-347 (Improper Verification of Cryptographic Signature) The product does not verify, or incorrectly verifies, the cryptographic signature for data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C