Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146
  • Date: Wed, 9 Sep 2026 17:21:50 +0000
  • Arc-authentication-results: i=2; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=H5AvSSke; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=VSV47WBB; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=H5AvSSke; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=VSV47WBB; arc=none smtp.remote-ip=54.240.27.123
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 0DA33413F3
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org E8E9740783
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975710; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=Fo7o3qvLDvtbAfTgZ6pHea9ZjmTgVUqCb0UIvc/SIhs=; b=fmyn4ZunhXYeQH4S7cU1jZ/+uqTAZyaOBMVjTG5vPFjE83DWCURVI3ZK4SrM+nwYY6Y/ 210g97byhiCIdWzvzM5DnW1dgymIodTPSbFDsclRNfFKg+lGXns7oOTbDNGaj3v4riPGW /BtH0agmnRzT/40QFPi56ycibYUJ2+Z1LwLM0GQhmBNhGwdEDyD43JNJECHJtOHklihup v7d6StU19jsY2grTeIOWd1hC0j7bCxnSaPfBrQ/tGOLQedySwbR1+/qq6KvPF+0sM7gLS PmrcalCYbq+CqPAMpIcgXmE2U9DxxsSL96FXIxthaAb70TS7RQVLsOioCXLkFkybKOA==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974511; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=ayrIcqBbHaVBEHMyNrE6jyct+k9PA8pQ7md8xjzBt58=; b=O2kqwwMod2m4wdvf24jUe468z88s8a1B32KsQH/o3fmk+aQ3ehV/yKsY3eb+YxZjwhJL mKacu23uULIy5SYywmMx/ByCo058afTGGObLNELm0ZhmK4OrTxyIUdIyBa5bMMevw3aUs spNItaJpkuO9Z6ycervCLjm3Y9dZqwPvLBbRNa89Q3p43spAmSLP3mLV03d4+hdjPiILA GiJ6fGDIl85NsRVHbwJyFUlyvGm++aaD/OzjYTd4CAlXfmxXwJchL1xeWufwpTUTYdPfz o383zpDIBtXfUE/fgGBSTaBgTC5DeQWJWctHcAIEJlsUlr0GmtIw2iuH7XOJCQSB9iQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975710; b=Y0Lp9th4zEiXDIeDQUXjrkWs3xm3r85X1UsCucVpcVISro9EFNnXc6H9tqleMsEnR22H q6ajl4+vxxtAw195Gh0Lp1dhVMF5p5NXu6UijYTUxFkeuW8T00zSh5Urut+asYMgaiq9w tV5s7/V8b1uKhONShoB7RlVRI0eVUzDmo/TupSGvhbxRIGbjkB82MIAXieen5dzofA3fE NOrMKcb+D5YbLgpsSqZOjLpEw1fjEEwYf4SVM7p9xsh9oLEYv0uICC/It18qELqDcs+YH Rqlzh3yFsA9pNvatFI+nJk639Wa1taqwHb8r7zh4K3ggE4gAdFK2Uh1qV8/fd5gbdRA==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974511; b=Y/elUxRlXj6Pb20Cmhh+W3mOAx9Y1Xa/iDxRr2O+AT4C80wJSfwZ+6fQIncdBqLtHTe7 Qc1vsCZWoYkk71QlaG1m8LV4rsSACvIbH4HDTjLb2+pi4evFbv0Wc0lM4fSN+vbkK0pBW I019Rr3/AKN3Mjkw8iNdcdJnR/N1Vj1w4LEbDI2CSIJML4i6TYkQHHG6LQ/HRn+hAdID9 5W6wdj9EYhzMUWx9HLRIHi73gw8X0Iy3UGuBzF+Uwx1QrOTia+ngwOMJ3StZzbzgexgkO ixIvhcSnP5/gCgn3+krd+CBUDwrS52C2oGsoVbZSrXjCtTxt5svPu/UX1h/NwzpUV/A==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/BMMLAX7VLRO5VUFT7UL5F5AKPLZILOGJ/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=XDcpk0cU; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=H5AvSSke; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=VSV47WBB; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-146

Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross-site scripting

Affected versions: <3.2.0
CVE IDs: CVE-2026-87948
Description: 
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.

The module does not sufficiently sanitize user-supplied data before
displaying it in generated HTML leading to a cross-site scripting
vulnerability (XSS).

Solution: 
Install the latest version:

* Upgrade to SAML SSO - Service Provider 3.2.0 [3].

Reported By: 
* Sudhanshu Dhage (sudhanshu0542) [4]

Fixed By: 
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]

Coordinated By: 
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/sudhanshu0542
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3602467

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang