Sustainsys.Saml2
SAML2 protocol support. Do not use directly, use the high level package for your platform.
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Jan 17, 2018
| Version | Released | |
|---|---|---|
2.11.0
minor
|
2.11.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.10.0
minor
|
2.10.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.0.3
patch
| ||
2.9.2
patch
|
2.9.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.9.1
patch
1 CVE
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev |
2.9.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.9.0
minor
1 CVE
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev |
2.9.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.8.0
minor
1 CVE
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev |
2.8.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.7.0
minor
1 CVE
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev |
2.7.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.0.2
patch
1 CVE
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev | ||
2.6.0
minor
2 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.5.0
minor
2 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
1.0.1
patch
2 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.0
minor
3 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5261
GHSA-g6j2-ch25-5mmv
Mar 25, 2020
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactToken Replay Detection is an important defence in depth measure for Single Sign On solutions. In all previous 2.X versions, the Token Replay Detection is not properly implemented. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. PatchesThe 2.5.0 version is patched. WorkaroundsThere are no workarounds with existing versions. Fixing the issue requires code updates. Referenceshttps://en.wikipedia.org/wiki/Replay_attack For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
Fixed in
2.5.0
References Updated Jul 08, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.3.0
minor
3 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5261
GHSA-g6j2-ch25-5mmv
Mar 25, 2020
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactToken Replay Detection is an important defence in depth measure for Single Sign On solutions. In all previous 2.X versions, the Token Replay Detection is not properly implemented. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. PatchesThe 2.5.0 version is patched. WorkaroundsThere are no workarounds with existing versions. Fixing the issue requires code updates. Referenceshttps://en.wikipedia.org/wiki/Replay_attack For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
Fixed in
2.5.0
References Updated Jul 08, 2026 · Source: OSV.dev |
2.3.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.2.0
minor
3 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5261
GHSA-g6j2-ch25-5mmv
Mar 25, 2020
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactToken Replay Detection is an important defence in depth measure for Single Sign On solutions. In all previous 2.X versions, the Token Replay Detection is not properly implemented. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. PatchesThe 2.5.0 version is patched. WorkaroundsThere are no workarounds with existing versions. Fixing the issue requires code updates. Referenceshttps://en.wikipedia.org/wiki/Replay_attack For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
Fixed in
2.5.0
References Updated Jul 08, 2026 · Source: OSV.dev |
2.2.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
2.1.0
minor
3 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5261
GHSA-g6j2-ch25-5mmv
Mar 25, 2020
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactToken Replay Detection is an important defence in depth measure for Single Sign On solutions. In all previous 2.X versions, the Token Replay Detection is not properly implemented. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. PatchesThe 2.5.0 version is patched. WorkaroundsThere are no workarounds with existing versions. Fixing the issue requires code updates. Referenceshttps://en.wikipedia.org/wiki/Replay_attack For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
Fixed in
2.5.0
References Updated Jul 08, 2026 · Source: OSV.dev |
2.1.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
2.0.0
major
3 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-5261
GHSA-g6j2-ch25-5mmv
Mar 25, 2020
Missing Token Replay Detection in Saml2 Authentication services for ASP.NET
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactToken Replay Detection is an important defence in depth measure for Single Sign On solutions. In all previous 2.X versions, the Token Replay Detection is not properly implemented. Note that version 1.0.1 is not affected. It has a correct Token Replay Implementation and is safe to use. PatchesThe 2.5.0 version is patched. WorkaroundsThere are no workarounds with existing versions. Fixing the issue requires code updates. Referenceshttps://en.wikipedia.org/wiki/Replay_attack For more informationIf you have any questions or comments about this advisory:
Affected versions
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
Fixed in
2.5.0
References Updated Jul 08, 2026 · Source: OSV.dev |
2.0.0
major
Dependencies (6)
Changelog
Compare changes
|
|
1.0.0
major
2 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.24.0
minor
2 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.23.0
initial
2 CVEs
CVE-2023-41890
GHSA-fv2h-753j-9g39
Sep 20, 2023
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactWhen a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a malicious identity provider to craft a Saml2 response that is processed as if issued by another identity provider. It is also possible for a malicious end user to cause stored state intended for one identity provider to be used when processing the response from another provider. An application is impacted if they rely on any of these features in their authentication/authorization logic:
PatchesPatched in version 2.9.2 and 1.0.3. All previous versions are vulnerable. WorkaroundsThe ReferencesThe patch is linked to https://github.com/Sustainsys/Saml2/issues/712 and https://github.com/Sustainsys/Saml2/issues/713 Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
1.0.2
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
+ 4 more Show less
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
1.0.3
2.9.2
References Updated Oct 14, 2024 · Source: OSV.dev
CVE-2020-5268
GHSA-9475-xg6m-j7pw
Apr 22, 2020
Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactSaml2 tokens are usually used as bearer tokens - a caller that presents a token is assumed to be the subject of the token. There is also support in the Saml2 protocol for issuing tokens that is tied to a subject through other means, e.g. holder-of-key where possession of a private key must be proved. The Sustainsys.Saml2 library incorrectly treats all incoming tokens as bearer tokens, even though they have another subject confirmation method specified. This could be used by an attacker that could get access to Saml2 tokens with another subject confirmation method than bearer. The attacker could then use such a tocken to create a log in session. PatchesVersion 1.0.2 and 2.7.0 are patched. WorkaroundsEnsure that any IdentityProvider trusted by the Sustainsys.Saml2 SP only issues bearer tokens if the audience matches the Sustainsys.Saml2 SP. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.23.0
0.24.0
1.0.0
1.0.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
Fixed in
1.0.2
2.7.0
References
Updated Sep 10, 2026 · Source: OSV.dev |