Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I wore the best smartwatch from Samsung, Apple and Google – here is how the Galaxy Watch wins 8

    August 7, 2025

    StableCoins were responsible for 90% salary paid in Crypto in 2024: Panera Survey

    August 7, 2025

    Google takes the study mode of Chatgpt with new ‘guided learning’ tool in Gemini

    August 7, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Important Samlife SSO defects log in as administrators as administrators
    Security

    Important Samlife SSO defects log in as administrators as administrators

    PineapplesUpdateBy PineapplesUpdateMay 21, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Important Samlife SSO defects log in as administrators as administrators
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Important Samlife SSO defects log in as administrators as administrators

    An important samlifee certification bypass vulnerability has been discovered that allows the attackers to transplant the administrative users by injecting the non -signed malicious claims in SAML reactions.

    Samlife is a high-level certification library that helps developers to integrate SAML SSO and single log-out (slo) in Node.JS applications. It is a popular tool for manufacture or connecting or connecting Identity Providers (IDPs) and service providers (SPS) using SAML.

    The library is used in developers and Federated Ident Management Stepsks integrating with corporate identification providers such as ezor ED or OkTA applying SSOs for mother -in -law platforms, internal devices, developers and federated Identification Management. It is very popular, measuring more than 200,000 weekly downloads on NPM.

    Dosual, tracked as Cve-2025-47949An important is (CVSS V4.0 Score: 9.9) Signature Rapping Dosha affects all versions of Samlife before 2.10.0.

    As Endorlabes explained in a report, Samlife correctly verify that the XML document providing the user identification is signed. Nevertheless, it proceeds to read a fake claim from a part of XML which is not.

    The attackers with a legitimate signed SAML reaction through the blockage or through public metadata can modify it to take advantage of the parsing defects in the library and to certify it as someone else.

    “The attacker then takes this legitimately signed XML document and manipulates it. They insert each other, malicious SAML claims in the document,” Endorlabs explain,

    “This malicious claim involves the identity of a goal user (eg, user name of an administrator).”

    “The important part is that the valid sign from the original document still applies to a gentle part of the XML structure, but the weak parsing logic of the SP will inadvertently process the incompatible, malicious claim.”

    It is a complete SSO bypass, allowing unauthorized distance attackers to increase privileges and log in as administrators.

    The attacker does not require a user interaction or special privileges, and the only requirement is accessible to a valid signed XML drop, which makes the exploitation relatively simple.

    To reduce the risk, it is recommended that the users upgrade version 2.10.0 released earlier this month to the Samlife version.

    Note that github Still provides 2.9.1 As the latest version, but NPM hosters Safe-to-use 2.10.0 as writing.

    There is no report of active exploitation of CVE-2025–47949 in the wild, but affected users are advised to take immediate action and secure their environment.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    administrators defects important log Samlife SSO
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAll new Google I/O features that you can try now
    Next Article Charles Schwab Challenge 2025: TV Schedule Today, How to Watch, Stream All PGA Tour Golf from anywhere
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Why I stopped recommending the pre -made SSD for Windows PC – and what to buy instead

    August 7, 2025
    Security

    Hacker extradited us to steal $ 3.3 million from taxpayers

    August 7, 2025
    Security

    Infostealers are age here. Is your financial services safe?

    August 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I wore the best smartwatch from Samsung, Apple and Google – here is how the Galaxy Watch wins 8

    August 7, 2025

    StableCoins were responsible for 90% salary paid in Crypto in 2024: Panera Survey

    August 7, 2025

    Google takes the study mode of Chatgpt with new ‘guided learning’ tool in Gemini

    August 7, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.