9.1
CVSSv3

CVE-2020-12676

Published: 02/10/2020 Updated: 30/04/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 571
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

FusionAuth fusionauth-samlv2 0.2.3 allows remote malicious users to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack".

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fusionauth samlv2 0.2.3

Exploits

Unauthenticated users can send forged messages to the FusionAuth to bypass authentication, impersonate other users or gain arbitrary roles The SAML message can be send to the application without a signature even if this is required The impact depends on individual applications that implement fusionauth-samlv2 Version 023 is vulnerable ...

Mailing Lists

############################################################# # # COMPASS SECURITY ADVISORY # wwwcompass-securitycom/research/advisories/ # ############################################################# # # Product: SAML v20 bindings in Java using JAXB # Vendor: FusionAuth # CSNC ID: CSNC-2020-002 # CVE ID: CVE-2020-12676 # Subject: ...

Github Repositories

SAML2 Burp Extension

SAML Raider - SAML2 Burp Extension Description SAML Raider is a Burp Suite extension for testing SAML infrastructures It contains two core functionalities: Manipulating SAML Messages and manage X509 certificates This software was created by Roland Bischofberger and Emanuel Duss (@emanuelduss) during a bachelor thesis at the Hochschule für Technik Rapperswil (HSR) Our p

SAML v2.0 bindings in Java using JAXB

fusionauth-samlv2 This repository is SAML v20 bindings in Java using JAXB You'd use this library to process SAML requests and responses See the tests for example code Security disclosures If you find a vulnerability or other security related bug, please send a note to security@fusionauthio before opening a GitHub issue This will allow us to assess the disclosure and