Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142
  • Date: Wed, 9 Sep 2026 17:20:14 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=I15MQxF6; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="xrYO9AL/"; arc=none smtp.remote-ip=54.240.27.35
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 8842842A14
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 2DF2F80E12
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975503; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=0mkcn20fvM9589qQAFDSh6IzoHTop8Ifev5jCt5Hp+E=; b=f8pIdv7w4Y2h73LH7Hoiz3CfPCrZuGPykNup+iAgIrVwwWIS5vkEuhLyBPGIOVgAb8Kb AL4HlLhx9Y9/xMhAqqcqxGKfRaNCYWPoLgoKkOrcv+g5oSXDBsSNfsMI1bRrDZglc5zxt glpClXCjNItZALKz3jFIdknm+0slWl1OdS0PPBlz8cZLE06qWw2qdczLP5Vo8TF32fc3K R0IcoHkd0KskuAoGhUHjG9relgM5IGtqxSzzA87B/NmCvLAFomwcEwv70m5qrCnRMVbYU aEkwcYQqadz43y3KEMWC4Hqx2TtvpddEhrgfRQljzHZbHxTr8VM9Q8O0vbTq4xGJxLg==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974415; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=YSgyxDv25OecTEXrYs6ysPvNfbEdsw2/N6KiajAZHXk=; b=DvQgnWWFejNpRxXerHuKU30Mu3JRJm32Ti3w1D9HV+TymaXAitES2QqFrG9+dm2k3h0M GSR6EDY3v9HTDpsBbLu9GAC89Qx/Ft/nhOBxU8TZ3l33NhCpVRecyNmUX56Ri1xZUQ5EY n0Miiqh+J8cnH/Gjx/3FigayFMyj7c40IsB+Ar/gHAotfkeYip7KNix9GbtcWZiGxx5et z5ei/9eJT0ONRxjbFjjM91av9bHP2CuI5ZO7kOmvMl1Uh8Gcmz+slnQHWp46aOCw8vOhG HF7pUV79iDoeNQLuEqptdWZEesPgHqQfwNotawEwiI3RqqP6xcXhP3DtQIrsGJvzP0Q==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975503; b=SdH6BRDTsJAcRrngksXm792sJprlYh/6jqoIPWc3m7IgGV5v03SD8e1w8vOI9O6xuwio S2sYSECVPOvm6vIoulvUhiWX6+ZyO233oV7sMIjyhPqca04MdCNjnVi5Nauc2z1ewcXT7 /Fi49T3lWBq92f2U6E7Bg62K9OGme0oL7KPINaerYN6gnivX4dsv4MP1g0wfCwxScK6tO 4AAVDHWnVEEbRHn+Nt7tNyiMBdZ1ukZPYn4V+DogB33rsnnW+8nRLA18HnXqnUt/fCZw9 XZ5IYyuOMHnOXRFJkg8oOvZAcfNszaYD1DUqJivGmq6pt+KKcOh+Nv5NUga2TH7iDuw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974415; b=Xw307QmfF8qDO0MKw3MPC300+xEunVHPOjh9VVz15tt3Swg8voQSwLyBZxmb87yGljoD muKW58COicMu9UTwLDsZn211jJ7+1/caknhghw7oVbGcY0WNXm9qd0/EQ2yLWW6R86ojN 1aoBt+F4P0LRONdVfLk8qaQnZ6Uxcgo/408aZIBTflPFC7lyX2ale7629BCdnncFe2pKh 4Bc7cFWClcnPYa4LDgP++3Eb7mp94LlxOjRLXPAMyHkjsOmapQlQUq39HTGHw4ryxRC1W NEBdYpKIuW4/7bLfdbux3DpK5bx3WoG9+43PmsX2Yg/3GFJfmNNoi5fMqF3C867os4Q==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/V6KJ2OWFAPJHDU2QHECIEK6EFMOWIB2S/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Q6m7V5M6; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=I15MQxF6; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="xrYO9AL/"; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-142

Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Critical* 15 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Improper certificate validation

Affected versions: <3.2.0
CVE IDs: CVE-2026-87944
Description: 
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.

The module does not properly validate TLS certificates when making outbound
HTTPS requests.

An attacker in a position to intercept network traffic could impersonate a
trusted remote service and influence communications performed by the module.

This vulnerability is mitigated by the fact that an attacker must be able to
intercept or redirect network traffic originating from the site.

Solution: 
Install the latest version:

* Upgrade to miniorange_saml 3.2.0 [3]

Reported By: 
* Jonni Kalpio (thatguy) [4]

Fixed By: 
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]

Coordinated By: 
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/thatguy
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621840

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang