CVE-2023-41890 is a high-severity vulnerability affecting the Sustainsys.Saml2 library, used in ASP.NET web applications acting as SAML2 Service Providers. The flaw allows a malicious Identity Provider to spoof SAML2 responses or a malicious user to manipulate stored state, leading to incorrect authentication or authorization decisions. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and can result in significant integrity impacts without requiring user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.3CPE matchmatch criteria | cpe:2.3:a:sustainsys:saml2:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.9.2CPE matchmatch criteria | cpe:2.3:a:sustainsys:saml2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.