Date
Severity
Critical
Vulnerability
Authentication bypass
Affected versions
<7.x-2.74

Description

This module enables you to perform SAML-protocol-based single-sign-on (SSO) on a Drupal site.

The module doesn't sufficiently block access, leading to a authentication bypass vulnerability.

Solution

Install the latest version.

If you use the SAML SSO - Service Provider module for Drupal 7, upgrade to miniorange_saml 7.x-2.74:


Reported by

Fixed by

Coordinated by