CVE-2025-24895
Last modified
CVE-2025-24895 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is based on the SAML2 standard which provides two entities: 1. Identity Provider (IDP): the system that authenticates users and provides identity information (SAML affirmation) to the Service Provider, in essence, is responsible for the management of the credentials and identity of users; 2. Service Provider (SP): the system that provides a service to the user and relies on the Identity Provider to authenticate the user, receives SAML assertions from the IdP to grant access to resources. The library cie-aspnetcore refers to the second entity, the SP, and implements the validation logic of SAML assertions within SAML responses. In affected versions there is no guarantee that the first signature refers to the root object, it follows that if an attacker injects an item signed as the first element, all other signatures will not be verified. The only requirement is to have an XML element legitimately signed by the IdP, a condition that is easily met using the IdP's public metadata. An attacker could create an arbitrary SAML response that would be accepted by SPs using vulnerable SDKs, allowing him to impersonate any Spid and/or CIE user. This issue has been addressed in version 2.1.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-24895?
How severe is CVE-2025-24895?
How do I fix CVE-2025-24895?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24889The SecureDrop Client is a desktop application for journalis…4.5
- CVE-2025-2489Insecure information storage vulnerability in NTFS Tools ver…6.8
- CVE-2025-24891Dumb Drop is a file upload application. Users with permissio…9.6
- CVE-2025-24892OpenProject is open-source, web-based project management sof…5.4
- CVE-2025-24893XWiki Platform is a generic wiki platform offering runtime s…9.8
- CVE-2025-24894SPID.AspNetCore.Authentication is an AspNetCore Remote Authe…9.1
- CVE-2025-24896Misskey is an open source, federated social media platform. …8.1
- CVE-2025-24897Misskey is an open source, federated social media platform. …8.2
- CVE-2025-24898rust-openssl is a set of OpenSSL bindings for the Rust progr…6.3
- CVE-2025-24899reNgine is an automated reconnaissance framework for web app…7.5
- CVE-2025-2490A vulnerability was found in Dromara ujcms 9.7.5. It has bee…5.4
- CVE-2025-24900Concorde, formerly know as Nexkey, is a fork of the federate…8.6
Are you affected by CVE-2025-24895?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
