SAML SSO - Service Provider
This module lets people log in to the website using a single sign on system linked to an external provider like Google or Microsoft.
The module fails to block access properly. A person without an account could skip the login process to enter the site. Once inside they could read any private information and change any data or website code.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate SAML SSO - Service Provider to 3.1.4.
For developers: what the fix changed
The fix uncomments `exit();` statements in `src/Utilities.php` to properly halt execution when SAML signature validation fails, preventing the authentication bypass.
Also in this release Added XSS filtering to test results and audience validation, and disabled network access in XML loading to prevent XXE.
src/MiniOrangeSamlAcs.php+7 −6src/Utilities.php+8 −8 fix