CyberRota Analysis
AI-GeneratedThe vulnerability allows attackers to exploit the lack of validation in the SAML <Conditions> element within Logto, potentially removing time and audience restrictions on assertions. This could lead to unauthorized access through replay attacks, posing a significant risk to systems relying on SAML for authentication. Organizations utilizing Logto for identity management should prioritize addressing this issue to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.