An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| samlify(npm) | 0 | 2.4.0-rc5 | N/A |
CVSS Metrics