OneLogin SAML-SSO Plugin < 2.1.6 - Authentication Bypass

2016-06-06 00:00
Jouko Pynnöne

Strategic Overview

Status
Patched in 2.1.6
Affected PluginOneLogin SAML SSO
Affected Version< 2.1.6
CVSS9.8Critical
CVEN/A
View all OneLogin SAML SSO vulnerabilities

Vulnerability Overview

The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in the ~/onelogin-saml-sso/onelogin_saml.php file in versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create new accounts, including administrator accounts if an existing administrator's role name, username, or email address is correctly guessed.

Technical Analysis

REMEDIATION: Update to version 2.1.6, or a newer patched version --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C