+
Skip to content

Releases: tngan/samlify

v2.10.0

25 May 06:36
Compare
Choose a tag to compare

Overview

Samlify version 2.10.0 addresses a critical security vulnerability (CVE-2025-47949) related to a Signature Wrapping attack in versions prior to 2.10.0. This release includes critical fixes to prevent attackers from forging SAML Responses to authenticate as any user. All users are strongly recommended to upgrade to version 2.10.0 to mitigate this risk.
Security Fixes

CVE-2025-47949: Signature Wrapping Attack Vulnerability

  • Issue: A vulnerability in Samlify versions prior to 2.10.0 allowed attackers to exploit improper validation of signed XML documents, enabling them to forge a SAML Response and authenticate as any user, provided they had a signed XML document from the identity provider.
  • Fix: Enhanced validation of signed XML documents to prevent Signature Wrapping attacks, ensuring secure SAML-based single sign-on (SSO) authentication.
    Impact: This vulnerability had a CVSS score of 9.9, indicating a critical severity. It posed a high-priority risk for SAML-based SSO systems.
  • Recommendation: Immediately upgrade to Samlify version 2.10.0 or later to address this vulnerability.

Ensure that your application is thoroughly tested after upgrading to confirm compatibility with your SAML-based SSO implementation.
References

GitHub Security Advisory: GHSA-r683-v43c-6xqv
CVE Details: CVE-2025-47949

Acknowledgments

We thank the security researchers and contributors who identified and reported this vulnerability, enabling us to deliver a timely fix to protect our users. @ahacker1-securesaml

Full Changelog: v2.9.1...v2.10.0

v2.9.1

24 Mar 14:41
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v2.8.11...v2.9.1

v2.8.11

02 Mar 04:21
Compare
Choose a tag to compare

v2.8.10

26 Feb 07:09
Compare
Choose a tag to compare

fix encryption for @xmldom/xmldom 0.8.6 upgrade #511 (@mastermatt)

v2.8.9

26 Feb 07:08
Compare
Choose a tag to compare

fix: system locale effects camelcase conversion #507 (@ayZagen)
fix: support unencrypted PKCS#8 keys again #503 (@mastermatt)

v2.8.8

20 Jan 08:40
Compare
Choose a tag to compare

v2.8.7

20 Jan 08:39
Compare
Choose a tag to compare
bump v2.8.7

v2.8.6

15 Oct 03:41
Compare
Choose a tag to compare

Upgrade @xmldom/xmldom to v0.8.3 to include the security patch (#492) @dan-diaz
Upgrade uuid version (#486) @andrew-m-civica

v2.8.5

24 May 14:33
Compare
Choose a tag to compare

What's Changed

  • Fixes issue with SAMLSignature method not using default transformations by @stjeffrey in #473
  • Makes normalizeCerString() handle inserted tabs (fixes issue with Okta) by @hackerceo in #481

New Contributors


This note is automatically generated.

v2.8.4

05 Apr 13:26
Compare
Choose a tag to compare
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载