CVE Database
/

CVE-2022-26493

Back to search

CVE-2022-26493

Published: Jun 3, 2022

Modified: Aug 3, 2024

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating existing users and existing roles, including administrative users/roles. This vulnerability is not mitigated by configuring the module to enforce signatures or certificate checks. Xecurify recommends updating miniOrange modules to their most recent versions. This vulnerability is present in paid versions of the miniOrange Drupal SAML SP product affecting Drupal 7, 8, and 9.

VendorProductVersions

Xecuify

Drupal 8 miniOrange SAML SP

affected
miniOrange Premium - < 30.5
affected
miniOrange Standard - < 20.3
affected
miniOrange Enterprise - < 40.4

Xecuify

Drupal 9 miniOrange SAML SP

affected
miniOrange Premium - < 30.5
affected
miniOrange Standard - < 20.3
affected
miniOrange Enterprise - < 40.4

Xecuify

Drupal 7 miniOrange SAML SP

affected
miniOrange Premium - < 30.2
affected
miniOrange Standard - < 20.2
affected
miniOrange Enterprise - < 40.2

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now