Descriptions

A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later.

Severity

  • CVSS Score: 9.1

Affected Versions

  • Armeria-saml versions less than 1.27.2

Fix

  • Armeria-saml should be updated to latest version (>= 1.27.2).

Reference

  • https://www.cve.org/CVERecord?id=CVE-2024-1735
  • https://github.com/line/armeria/security/advisories/GHSA-4m6j-23p2-8c54

Updated: