it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Insufficient replay protection - SA-CONTRIB-2026-150
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Insufficient replay protection - SA-CONTRIB-2026-150
- Date: Wed, 9 Sep 2026 17:23:15 +0000
- Arc-authentication-results: i=2; smtp3.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=E4OU2RPG; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=vNQl23ud; arc=none smtp.remote-ip=54.240.27.38
- Arc-filter: OpenARC Filter v1.3.0 smtp3.osuosl.org BD86B6F837
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 126E24065E
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975913; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=ntmTsXpP8ugOXdRK+GtU1oHv9RN3detwCztrpsYaQSo=; b=EpZjbtYpF2fR1lrSgtG+hOHYY2Q0KKlQ3cWaE82GaZRMfowZUFZCil/6cY6m/MfNl4cs tf+1XwSJFfBSKUuahUP//Pig2xz8d9ZqVkkQ641qXNi8Vnuad/jkPJmUlSrOJm2vduth+ t33j2qBGpBNzKyNzMTV2UCI4YDdSFpzOxnVEODeMo8zDvLorYAw9eMwWgu4uxlffkJhGt 0m5YpGwPjtmWvEFxy6iYKqEG/JkXgGjHPb6eYxdZDsfEOmdGZPWMyGKvnypgf8nMgepKn BksMtG954ja/3x54UFTtN+nLWdsjQhL2qIns4dpTIuT4AdT6cIGQ8O9W8W8nAUqFeOw==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974597; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=eyE2gAy9bqRBLyLyDHlJOZnd2FVwuwsZos3u/5GQZNE=; b=JkLly804Xvb4YP2uTru27c/Fqe1PxXp7zTwesd8oZP0kshAbrFnwpCFaNa8owWoUHVGL dIiurpYnaJvRSklyc5ucz0gxa93HkagKNM2ZflfhepwGwlkzHk72IAOS84NSHUz1Ngg6X +lDCVFawzHB1+S6TLEPuvng2Z0a6zQ0N4fughLkPPkQYdp5EINw3W2984R4QloygqaCR/ 10bPebuwJ+MBfdk6UkUqyAtTbk5UBh35ROCiDwIp13RIY7l/49A3mEmInMSrmJaqiWu/P BeO4DHIy4RcWySQQb9UYwNvx1CALm/hWadP0d6XUtf5c1E31xrEQMatJR8IdedjgNCA==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975913; b=Ibm+Svonsacc4mB/Ug0nNej+DfqM2dEK0XWbLEW7ZzpLe5ycPj8LNbpAJdeKL/HAZrCE lsS98XdMFV93HgesFWio6bi7DNrJQIvVELpP3V9kvCznmAEL3f+aOq274uWKKfB4t1uwG j+gLMVfFttziJ9G19BoXbI5sbdjG6ezMuK12SMCq0M3LH+MeZn7HS60okRXJZnWZezQZw 7RyulxtzISGW4SZk2oJp8baBQ/F8twLDVjixJhpqNtlhl/x5rMe35hRxWVff6DlNHJyXe I1N951ADWJTysnHltypfGpsX5gzfV79HwvuEBzUjJhmGk1auLUn/ltrvqmyp8iAjW1Q==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974597; b=C/ZCWvwG/buxam2KHueHSeBVMVNEVST3lrPfdczeY532tdSIG8zWWYqHXPJTImUL25Vz 0V8I6HNefJ0XTdJW5LyOxdgr2rflruqKFFkQolDol4LgQsEs/VBTXDf27GXVn8+VARDm/ gkFIcFFNN4cARBCfvcZCy/o/j9aJ6NCrDzhlg6Iyej+Y+NfIdJpQSGDIxLXS8tpJu+WTO RIvG0qI8W/haESJdnihv8dcmaX6kNK/WzLuQGytCbroWsc6Dt+UPqhj9jWgLsoa2gEsDD pOKL/QI6xnOz48v1SG0d3cI0AZBDX30b8Uae/iUpIR+sLZpSLK5Edd53/zMzg1X4ZnQ==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/EOB6GYPELLPY3UJNQF4L37GHBBRRT6LH/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="ga/nw/uQ"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=E4OU2RPG; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=vNQl23ud; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-150
Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Moderately critical* 10 ∕ 25
AC:Complex/A:User/CI:None/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Insufficient replay protection
Affected versions: <3.2.0
CVE IDs: CVE-2026-87952
Description:
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.
The module does not sufficiently prevent reuse of previously accepted SAML
assertions. Under certain circumstances, a valid assertion may be replayed
within its validity period, potentially allowing repeated authentication
attempts using the same assertion.
This vulnerability is mitigated by the fact that an attacker must first
obtain a valid SAML assertion and can only reuse it during the assertion's
validity period.
Solution:
Install the latest version:
* Upgrade to miniorange_saml 3.2.0 [3].
Reported By:
* Brian Willows (hsjbrianwillows) [4]
Fixed By:
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]
Coordinated By:
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/hsjbrianwillows
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621927
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Insufficient replay protection - SA-CONTRIB-2026-150, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.