it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148
- Date: Wed, 9 Sep 2026 17:22:35 +0000
- Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ZYBDnsCh; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=aZRX8mC6; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ZYBDnsCh; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=aZRX8mC6; arc=none smtp.remote-ip=54.240.27.34
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 37B2A42E84
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 9352A400BC
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975806; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=NH8rOh76+5AdWzn6aiJnV1ph6EiurKykyvlgERuUW+A=; b=eYf7Y+monxVNFr6GDBmHyTa0dR9ugmCG1inDYLNLwKNF/FM98id7K4BaPNayNlVKOrtj GJX0OYdxngg4ap32uD4LtTyiGjsiqIt/SfmqYw+Y6xlQH9JfqN6Htu8Lp2SnWvtFmntBe umzMDUEPS/CnAvjRNpSLASBbq9Ob9vDtfaid61EfxksNm40Cirn3Xg9oK528J8fQTwNgP uI0CPsuQiVQsNvF/U03xzdvoe97a9CpdBN/DJ6KX+HGpOCQ0K8RpWH32Lx6mxQouI19Ud GBVnvxghuXN0nAjsJNARzKvRszs5EGJdg+kDQsSaD6Zg/bLakRXAuHgPUJksj61vwUw==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974556; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=2pPJxl2wh1hJd0Pee+d5mM1qISKS6Ro3LBdEoI5abSk=; b=TN6hycsZ2Q3jpDAZlutNDy+xGtSSO9vwGA+xKGGxqGKRfPUUkQWEKmuxkPUUNBXu/PZR dM4C0UbbgKq2TogeTnJYTon4orHEi+0xuXxh6o20gVxGoxM9gBOOFLzAPFX0QJJVf6Phw kKGZNE0G6y/HCeWhFdJjvqaiRmUpKrPVKEUYHLGGCAYOW3frkCnvJrH4o1Si8A04bRVLn PhQf7x/zxCywdDfTSReTEalLUI9xs7QfbFYTIAaSrfF+N/YrZwB1LdzXwj0qQD74nBuMI vNbwNPHIuTMhZpmB+vQbqUpYdwtaXZvRRZK3s5UJQSSEiBe7MXzdncFbnuei2cOvVHg==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975806; b=DJz4bPGaHerPY/aJVGGM5KC4A5AHoASO1++r0SINsRNkxjIAuI4kiSP9swzOkHH/QJ1+ RauRsDqXPdg3CiM+2DUA2pdLpvVQbgtfpA7iNUTA4LfHNV9O/4VLb3/ly9Y3jFVd2SQd1 8H8fOSnnWONLM/9akC13MZLn2cdSX0VH6+VH47Bwe4qMYljXE2wUNd5nHd7fcfNzcXagy uRSYBIuljSeQ4nW5fGTBxI1DfBoVeiIjOYI3G/vBsJ1uj7StTcnhBLXaRKkM7YvZdMN5E sR+8eJ/dn2GMI2NiyqmpJGVIzsnjoUHFSc0zJuMtTcmncMegJuDiHGd6IMDWELgCzvg==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974556; b=fzbhPQtpphWEoYXcdUiP5R0hkBDaJbm5lcFbOFJ09wQuStJzC3pEw5p6sk7E+bFh4Xxt 3LsKs6pNBAMwyvASMBPXBrgB6hTBzfkjzmfzvFdcHPTAYwQvjRFxYHZOOqQ3wvQ16zXhk NmArU3UA8svP+CQGehtsv4ddow9eKCpE5QxGcmc7tuQD5gCOXFD88u020m5HB0Cu379WH koUTfw9lrOXiZyz7t0r4eUQF6d8WGYOfed074IY0QA+9YwBLcNBBpbIL5XBgBSYf2ZQ2K V9Tnb0RAY4Phww40c8Jd7jXGhO9sGGndL3TwPIc1lv3Ismp+JmdOrvbd+eTrfCeEO7w==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/NHFISU3N5QKRLI3H5MSJXHPP5RTHU22Q/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=BUCDf4v4; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ZYBDnsCh; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=aZRX8mC6; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-148
Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Moderately critical* 13 ∕ 25
AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2]
Vulnerability: Embedded credentials
Affected versions: <3.2.0
CVE IDs: CVE-2026-87950
Description:
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.
The module contains embedded credentials used by the functionality provided
by the module.
Under certain circumstances, these credentials could allow information about
associated services to be disclosed.
Solution:
Install the latest version:
* Upgrade to miniorange_saml 3.2.0 [3].
Reported By:
* Sudhanshu Dhage (sudhanshu0542) [4]
Fixed By:
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]
Coordinated By:
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/sudhanshu0542
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621862
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.