Impact
A single vulnerability in the Kong SAML plugin allows an attacker to bypass authentication by supplying an unsigned SAML assertion when the validate_assertion_signature option is false, which is the default setting. Because the plugin trusts the assertion without verifying a cryptographic signature, an unauthenticated remote attacker can create a crafted SAML response that is treated as a valid login for any user, including an administrator. This flaw, a CWE-288 improper validation of cryptographic signature, directly affects the confidentiality and integrity of user identities and can lead to full system compromise.
Affected Systems
The affected component is Kong Enterprise Gateway’s SAML plugin. The plugin has the validate_assertion_signature option disabled by default, meaning the vulnerability applies to deployments that have not manually overridden this setting. Specific affected versions are not listed in the advisory, so all builds of Kong Enterprise Gateway containing the SAML plugin that rely on the default configuration are potentially vulnerable until a patch or configuration change is applied.
Risk and Exploitability
The CVSS score of 7.7 reflects a high severity due to the remote access, privilege escalation, and potential confidentiality and integrity impact. However, the EPSS score is below 1%, indicating that current exploit activity is very low. The vulnerability is not present in CISA’s KEV catalog. Attackers would need to send a crafted SAML assertion to a target Kong Gateway that accepts unsigned assertions, which is achievable over the network with reachable endpoints. If the gateway is exposed to the public internet and the default plugin configuration remains unchanged, an attacker could impersonate any user without authentication.
OpenCVE Enrichment