CVE-2018-5387
Last modified
CVE-2018-5387 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.. EPSS estimates a 1.66% chance of exploitation in the next 30 days.
Description
Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wizkunde | Samlbase | < 1.4.2 |
References
- https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementationsExploit, Third Party Advisory
- https://github.com/GoGentoOSS/SAMLBase/commit/482cdf8c090e0f1179073034ebcb609ac7c3f5b3Patch, Third Party Advisory
- https://github.com/GoGentoOSS/SAMLBase/issues/3Issue Tracking, Patch, Third Party Advisory
- https://www.kb.cert.org/vuls/id/475445Third Party Advisory, US Government Resource
- https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementationsExploit, Third Party Advisory
- https://github.com/GoGentoOSS/SAMLBase/commit/482cdf8c090e0f1179073034ebcb609ac7c3f5b3Patch, Third Party Advisory
- https://github.com/GoGentoOSS/SAMLBase/issues/3Issue Tracking, Patch, Third Party Advisory
- https://www.kb.cert.org/vuls/id/475445Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5387?
How severe is CVE-2018-5387?
How do I fix CVE-2018-5387?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5381The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bu…6.5
- CVE-2018-5382The default BKS keystore use an HMAC that is only 16 bits lo…4.4
- CVE-2018-5383Bluetooth firmware or operating system software drivers in m…6.8
- CVE-2018-5384Navarino Infinity web interface up to version 2.2 exposes an…
- CVE-2018-5385Navarino Infinity is prone to session fixation attacks. The …
- CVE-2018-5386Some Navarino Infinity functions, up to version 2.2, placed …
- CVE-2018-5388In stroke_socket.c in strongSwan before 5.6.3, a missing pac…
- CVE-2018-5389The Internet Key Exchange v1 main mode is vulnerable to offl…
- CVE-2018-5390Linux kernel versions 4.9+ can be forced to make very expens…7.5
- CVE-2018-5391The Linux kernel, versions 3.9+, is vulnerable to a denial o…7.5
- CVE-2018-5392mingw-w64 version 5.0.4 by default produces executables that…
- CVE-2018-5393The TP-LINK EAP Controller is TP-LINK's software for remotel…
Are you affected by CVE-2018-5387?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
