Project:
Date:
2020-November-18
Vulnerability:
Access bypass
Affected versions:
<2.14.0
Description:
This module enables your users residing at a SAML 2.0 compliant Identity Provider to login to your Drupal website.
The module has two Authentication Bypass vulnerabilities.
Solution:
Install the latest version:
- If you use the miniorange_saml module for Drupal 8.x, upgrade to miniorange_saml 8.x-2.14
- If you use the miniorange_saml module for Drupal 7.x, upgrade to miniorange_saml 7.x-2.54
Reported By:
- Heine of the Drupal Security Team
- Michael Mazzolini
Fixed By:
Coordinated By:
- Heine of the Drupal Security Team
- Chris McCafferty of the Drupal Security Team