Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149
  • Date: Wed, 9 Sep 2026 17:22:57 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=bZ5EQegb; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=b0FFtGnk; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=bZ5EQegb; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=b0FFtGnk; arc=none smtp.remote-ip=54.240.27.116
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org DE1E1429E7
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 11CA2400BC
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975854; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=A5+EqNd+Tf8INrJIw/c0T95Lc1o1n7D/hGjNmJh58ts=; b=KwKhvGnyF8wx+SFo7KjTzguBjUPs+iUPYLa7gqglc/q3lDZuDkP1PR1Udrvl2SM5nm+3 td6/gU1BTuMB41qGNIegBFca5TftPjY8/MTK9PTdhsKaBYL3f4cHEbh7a/4829rgKje4o Bk3/uEZBh4M9coHeOTGJwQ9ZvMS0SiugQr85qQlAd8R1VsZEK+1yAZjuuNvrzd0njyMn+ QVigwDBgB1CYzWVsHHkRbyzNyPX54WXMswM6iFWI5aIUMg2kDuP5YugEoQ/SGK96UuA0m vPkoC+QLQe5+5mePa0XDeCt/++L8uGZRLzzf8Mgr5aWgFI6Kd/J6jkAUzDkzGNiulGQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974578; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=lauVty1b9RV0g/YozQpO7L0BCb4RZT3KziRuWAkl9bo=; b=IcuQoB9kBx3uilqKBQgWEzm1O1RRzbQsiTHIQMJBObuFSxlydoNwLivNBuugr+eWoK3c 3/I9SdxJ/ubAFUfZ1l4EjI13H6Aqlgg3RYuc1LiTOe72LkEXTm99LQ7+m/u4pDZep0THf 2EglgJZcq/2wrlVDcvmcW/6jv5IOI6RjxaV5GdaEzh0nYmItT4EmcSG7Av+qsU1vEtU62 ybggvCJUWzfBAurpWrl4WhiSxWNJCD9QumOPyLCaDZ8BX18foBz4rinFd0Mpz5KNdN6fe Xhda0I0C1vKHGXUVr3lLYDiD/kdiAASbCExgri51IGPDLHaLAECQo4VUUaKA6jF/stQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975854; b=lkgMqy1+nbrrpmRXBb2BqXejT9/scW4Yp075BTp4JK9O3344yR8E1IjMneNIGvFm/WcR ZGmFec+n0c+9tCQNyvIokTbmK3hQYrX1SiO8ux5hcmhA8VwZ0VEWILODMoNXF7CELkZbs 8GB4kI3Bw9bWslmtens1N0WK7+cy4p2VpVsE4THqY3NcE8pCKJDeqYjs2hOFe93iTjc3y daNPOSqF2rHgkBy+9AhsArS8JD9cgG+SkMR9h+LeIyPL60s/sqLn7F+s3Vb9bztoy5Q+B 8mscf0ppJJJcL5IL8RT2pc8n5a1aVWu/wGW5oboPlW+HatIrKVca/N4kfbKN3JqFwLQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974578; b=fRkzwcL/nOs8UrOsT/TlltJ78dtPSC3i1IfFdHrnq1aGS8mcBwJznEmNsUT6lROuFWgl Q7HJ0qnWupRE8AiAUV8nx2AASId9kpsGEwPaiYwWLjRdwEBLr1R66G9WW6cOIJ8UYL0LN alSgIjW5msqziR4nGK69FHFvglhw3eCtFLUvQ5fnz4Dc2QpxxhUCYlARVYqUrQDjTw7vo bqOa+Y+Y1RR+yvzRs9OjfbdKGXo3pQEyf0NDMPKWOv2vd+Wk/N3eSmc9hwM0LLKY84lKf Nyn3XmAwWXp1DiEwkLs6LNJMfPpTbP5FocYoJCNl5F4ham3DKn/UaO7Ukzlhte3JTdg==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/DPMCIHGD6I5XPRX253LC3HIX6CJCGRQY/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=WjVBIxBn; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=bZ5EQegb; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=b0FFtGnk; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-149

Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Moderately critical* 12 ∕ 25
AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Information disclosure

Affected versions: <3.2.0
CVE IDs: CVE-2026-87951
Description: 
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.

The module stores sensitive authentication information in a manner that could
allow disclosure to users with access to configuration or related system
data.

This vulnerability is mitigated by the fact that an attacker must first
obtain access to configuration or underlying storage mechanisms.

Solution: 
Install the latest version:

* Upgrade to SAML SSO - Service Provider 3.2.0 [3].

Reported By: 
* Sudhanshu Dhage (sudhanshu0542) [4]

Fixed By: 
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]

Coordinated By: 
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/sudhanshu0542
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3603951

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang