216.73.217.22

CVE-2025-54419

· Published 28/07/2025 20:17 · Modified 29/07/2025 14:14

Labels: CVE-2025-54419 2025-07-28CVE-2025-54419CWE-287[email protected]

Essential information

Published
28/07/2025 20:17
Modified
29/07/2025 14:14
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CVSS metrics

Description

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an attacker to modify authentication details within a valid SAML assertion. For example, in one attack it is possible to remove any character from the SAML assertion username. To conduct the attack an attacker would need a validly signed document from the identity provider (IdP). This is fixed in version 5.1.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
node-saml / node-saml cpe:2.3:a:node-saml:node-saml:5.0.1:*:*:*:*:*:*:*
node-saml / node-saml cpe:2.3:a:node-saml:node-saml:<5.1.0:*:*:*:*:*:*:*

References