Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times even when the current time is past the NotOnOrAfter. This could impact the user where they would be logged out from an expired LogoutRequest. In bigger contexts, if LogoutRequests are sent out in mass to different SPs, this could impact many users on a large scale. This issue was patched in version 4.0.5.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-08-23T20:15:23.057Z

Updated: 2023-08-23T20:15:23.057Z

Reserved: 2023-08-09T15:26:41.052Z


Link: CVE-2023-40178

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-23T21:15:08.877

Modified: 2023-09-05T14:57:10.410


Link: CVE-2023-40178

JSON object: View

cve-icon Redhat Information

No data.