Vulnerability Description
FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fusionauth | Samlv2 | 0.2.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/159454/FusionAuth-SAMLv2-0.2.3-Message-ForgExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Oct/1ExploitMailing ListThird Party Advisory
- https://compass-security.com/fileadmin/Research/Advisories/2020-06_CSNC-2020-002ExploitMailing ListVendor Advisory
- https://github.com/SAMLRaider/SAMLRaiderThird Party Advisory
- https://www.nds.ruhr-uni-bochum.de/media/nds/veroeffentlichungen/2012/08/22/BreaExploitThird Party Advisory
- http://packetstormsecurity.com/files/159454/FusionAuth-SAMLv2-0.2.3-Message-ForgExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Oct/1ExploitMailing ListThird Party Advisory
- https://compass-security.com/fileadmin/Research/Advisories/2020-06_CSNC-2020-002ExploitMailing ListVendor Advisory
- https://github.com/SAMLRaider/SAMLRaiderThird Party Advisory
- https://www.nds.ruhr-uni-bochum.de/media/nds/veroeffentlichungen/2012/08/22/BreaExploitThird Party Advisory
FAQ
What is CVE-2020-12676?
CVE-2020-12676 is a vulnerability with a CVSS score of 9.1 (CRITICAL). FusionAuth fusionauth-samlv2 0.2.3 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".
How severe is CVE-2020-12676?
CVE-2020-12676 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-12676?
Check the references section above for vendor advisories and patch information. Affected products include: Fusionauth Samlv2.