it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Server Side Request Forgery - SA-CONTRIB-2026-151
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Server Side Request Forgery - SA-CONTRIB-2026-151
- Date: Wed, 9 Sep 2026 17:23:35 +0000
- Arc-authentication-results: i=2; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="T5EZwX/8"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=SO0Vt5I9; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="T5EZwX/8"; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=SO0Vt5I9; arc=none smtp.remote-ip=54.240.27.116
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org B23D7453D7
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org E15984065E
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975950; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=SpykcWE6W8nqHgEidyoFLJ6bIKW4oDSaVwBJnJvxbdk=; b=PrSonklHKWjIbtSJ/meKM1u0FNPE/IO2FGwD4kBrJ52usK7wtMF92zaFnnU00mzhZ4Mm LC0GAxrPpTUeIt/dLKHn784xhGafHZ+paV9L+OeVNZFNGE6OFy91doSv14R2lc2hoKghN NQ5C2VtCDetgVUmvdUGv6eGiNMr7P4bTXkPPcbr7Ndj5YEXfIqlJhsS7AVg6ZJ1o4LPAP zQu7ejW3X0pwiTIH+mGyewHvhbOqzgANtF6FPfgc2vCG2sZWvZGkqeFPSJ7TxL7JLOaI9 Q+H9pHrcLscBiIaZSe7W6UEoagZQ0C2om5L8+oGJ2iIiPL/VqktU+o9y8OKfyEHsOFg==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974617; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=M4R0zAa+FsUb5R4RhHpRsfFgcxyjOGN7uDXNevHjS+M=; b=H9S726EgLJxeJZCF9o25QR4d/qZZBtYrF5FaQ8wj+n9Yz2nrzitBnSPmkLcWYnCb68+3 Km5pnh7cm0nQp6ZdhSaNPume+fnwKIa6kWxGJbc30ExvUTkuiVCRMdEchyfiAgLvNZPLc hF0iAGi+g5E10RdNDHkoRMfYEiaOn1Uq+OhQ88oPdxvKO5MYO38RyRgjvHSu52O1+J1QH vLiRXMjq6S9uHXsYTg1unJVXTeGklDs5HgdVmnJAMXPbOdlliNH+q2edZIQ7WxjCV9A5n 0xUOK3x3m/ij9R88po/w+S+t7yZZrutaRMSzrBQoKTSmQLkvcEBso5KbpDx5ldumaWw==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975950; b=G5nFaMzb5sdm5HzxeM5Hnz1ViteKdqdVGPdKOgE26ZyMMMmC8/BHLfVuK7YEY4Hu9X+f mNsQh7NIDEvlorG+jXB64TlJj7KYdrYFOulTJ1lnv6JgPySKv0CJUJ2GcJh529I9PFypu dDFyygaUaHthv0+Wd6fu1O+3GVvyf6qiga9VEFHQtLh/PrI+F5Bk/rti5slsQjokyVBOH n2M4bfB2m8ymE1IIMdWuKt2yRzK46HiZOV8NQLU9xQVWOLGjgcJnl87PW1wg/rAMMYema BWnK7TpnENw2oPgYCVLMTAUwDTIzHAHy/hPLs94Xe7xaUBZ0PA7SPMxWqpPDIrHvJZg==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974617; b=QdSqqTzkVSrGUumFScbJ29t+jkFPyUMtk9SGMWiNHkHREcerKJl+CDFEvt9+LhIxMBZn eX52fUnCfZnd8QQpn+GXCBSCHwA3TmF0Z3d24eWCCi3Ls9FKpqYpbD36Trjd1BLmyKCeQ FrPGfzEQKv6ZZhGIoqu7Ch8sW6Jz/mqxNmjOdHDmjqA3UHLZo8/lIT0IEM56o0HZBJwRT jTz9NfPSAgV6Z7la1gE/QY4BSbLkkAtrK8n5vfQoRMga69wANXgeg30exqSqQQvi6Cgo1 0zUKGChfFKGJFpcu5EcGWtyw8WkKztyZHnssJFiRDPY5a6k0FuhokNVVdfxWCUqqrMw==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/UPSNQXFELWHCOYE6YVNQCDQUCLYZ7DJR/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=P0FIwAKw; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b="T5EZwX/8"; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=SO0Vt5I9; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-151
Project: SAML SSO - Service Provider [1]
Date: 2026-September-09
Security risk: *Moderately critical* 11 ∕ 25
AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Server Side Request Forgery
Affected versions: <3.2.0
CVE IDs: CVE-2026-87953
Description:
This module allows you to configure your Drupal site as a SAML 2.0 Service
Provider so that users can authenticate through an external identity
provider.
The module does not sufficiently validate URLs obtained from identity
provider metadata. An attacker with the ability to configure identity
provider metadata could cause the application to make requests to unintended
destinations, potentially allowing access to internal network resources.
This vulnerability is mitigated by the fact that an attacker must have
permission to configure identity provider metadata.
Solution:
Install the latest version:
* Upgrade to miniorange_saml 3.2.0 [3].
Reported By:
* Brian Willows (hsjbrianwillows) [4]
Fixed By:
* Roushan Kumar Singh (roushan59227) [5]
* Sudhanshu Dhage (sudhanshu0542) [6]
Coordinated By:
* Bram Driesen (bramdriesen) [7] of the Drupal Security Team
* Greg Knaddison (greggles) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team
* Swan Kalata (akalata) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/miniorange_saml
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/miniorange_saml/releases/3.2.0
[4] https://www.drupal.org/u/hsjbrianwillows
[5] https://www.drupal.org/u/roushan59227
[6] https://www.drupal.org/u/sudhanshu0542
[7] https://www.drupal.org/u/bramdriesen
[8] https://www.drupal.org/u/greggles
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://www.drupal.org/u/akalata
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621926
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] SAML SSO - Service Provider - Moderately critical - Server Side Request Forgery - SA-CONTRIB-2026-151, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.