logo

Database

Asymmetric denial of service In passport-saml

Description

Unlimited transforms allowed for signed nodes

Impact

A malicious SAML payload can require transforms that consume significant system resources to process, thereby resulting in reduced or denied service. This would be an effective way to perform a denial-of-service attack.

Patches

This has been resolved in version 3.1.0. The resolution is to limit the number of allowable transforms to 2.

References

https://github.com/node-saml/passport-saml/pull/595

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions