CyberRota Analysis
AI-GeneratedThe vulnerability allows attackers to bypass authentication in the Samly library by reusing captured SAML assertions, enabling them to impersonate legitimate users. This critical flaw arises from the lack of enforcement of the SAML 2.0 requirement for single-use assertions, making it possible for attackers to repeatedly authenticate until the assertion expires. Organizations utilizing the Samly library version 0.3.0 or later should prioritize remediation to prevent unauthorized access to their systems.
Original NVD Description
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose default duplicate detector is a no-op. The /3 arity accepting a DuplicateFun exists in esaml and implements the check, but Samly never calls it and offers no configuration to supply one, so the SAML 2.0 Web Browser SSO Profile requirement that a bearer assertion be used once is unenforced. An attacker holding a valid SAMLResponse obtained from the network, from browser history, or from logs can submit the identical bytes repeatedly until the assertion's NotOnOrAfter passes, each time establishing a session as the assertion's subject. This issue affects samly: from 0.3.0 onward.