CVE-2025-46572 Details
Description
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be done by using a valid SAML object that was signed by the configured IdP. Users are affected specifically when the service provider is using passport-wsfed-saml2 and a valid SAML document signed by the Identity Provider can be obtained. Version 4.6.4 contains a fix for the vulnerability.
A vulnerability in passport-wsfed-saml2, affecting versions 3.0.5 prior to 4.6.4, allows attackers to impersonate users during SAML authentication by crafting a SAMLResponse. This exploitation involves using a valid SAML object signed by the Identity Provider (IdP). Users are specifically vulnerable when their service provider employs passport-wsfed-saml2 and they can obtain a valid SAML document from the IdP.
Users can upgrade to passport-wsfed-saml2 version 4.6.4 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 6, 2025CISA-ADP
Assessed May 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/auth0/passport-wsfed-saml2/commit/e5cf3cc2a53748207f7a81bfba9195c8efa94181 | [email protected] | Source CodeVendor |
| https://github.com/auth0/passport-wsfed-saml2/security/advisories/GHSA-wjmp-wphq-jvqf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| auth0/passport-wsfed-saml2 | >= 3.0.5, <= 4.6.3 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2025 | CVE Modified | [email protected] |
| May 7, 2025 | CVE Modified | [email protected] |
| May 6, 2025 | New CVE Received | [email protected] |
Volerion