{"id":"GHSA-4mh8-9wq6-rjxg","summary":"OpenAM vulnerable to user impersonation using SAMLv1.x SSO process","details":"### Impact\nOpenAM up to version 14.7.2 does not properly validate the signature of SAML responses received as part of the SAMLv1.x Single Sign-On process. Attackers can use this fact to impersonate any OpenAM user, including the administrator, by sending a specially crafted SAML response to the SAMLPOSTProfileServlet servlet.\n\n### Patches\nThis problem has been patched in  OpenAM 14.7.3-SNAPSHOT and later\n\n### Workarounds\nOne should comment servlet `SAMLPOSTProfileServlet` in web.xml or disable SAML in OpenAM\n```xml\n\u003cservlet\u003e\n    \u003cdescription\u003eSAMLPOSTProfileServlet\u003c/description\u003e\n    \u003cservlet-name\u003eSAMLPOSTProfileServlet\u003c/servlet-name\u003e\n    \u003cservlet-class\u003ecom.sun.identity.saml.servlet.SAMLPOSTProfileServlet\u003c/servlet-class\u003e\n\u003c/servlet\u003e\n...\n\u003cservlet-mapping\u003e\n    \u003cservlet-name\u003eSAMLSOAPReceiver\u003c/servlet-name\u003e\n    \u003curl-pattern\u003e/SAMLSOAPReceiver\u003c/url-pattern\u003e\n\u003c/servlet-mapping\u003e\n```\n\n### References\n#624\n","aliases":["CVE-2023-37471"],"modified":"2023-11-11T05:17:29.367431Z","published":"2023-07-20T18:54:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-20T18:54:13Z","nvd_published_at":"2023-07-20T17:15:10Z","cwe_ids":["CWE-287"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/security/advisories/GHSA-4mh8-9wq6-rjxg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37471"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/pull/624"},{"type":"WEB","url":"https://github.com/OpenIdentityPlatform/OpenAM/commit/7c18543d126e8a567b83bb4535631825aaa9d742"},{"type":"PACKAGE","url":"https://github.com/OpenIdentityPlatform/OpenAM"}],"affected":[{"package":{"name":"org.openidentityplatform.openam:openam-federation-library","ecosystem":"Maven","purl":"pkg:maven/org.openidentityplatform.openam/openam-federation-library"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.7.3"}]}],"versions":["14.5.2","14.5.3","14.5.4","14.6.1","14.6.2","14.6.3","14.6.4","14.6.5","14.6.6","14.7.0","14.7.1","14.7.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-4mh8-9wq6-rjxg/GHSA-4mh8-9wq6-rjxg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}