Impact
Logto fails to validate the SAML <Conditions> element in incoming assertions, a weakness classified as CWE-345, allowing an attacker to remove time and audience restrictions. This flaw permits replaying old assertions without limitation, effectively bypassing the intended authenticity checks and enabling the attacker to gain unauthorized access to protected resources. The vulnerability directly undermines the integrity of the authentication process by allowing a pre‑signed assertion to be abused indefinitely.
Affected Systems
The affected application is the Logto platform provided by Logto. No specific version information is available from the current data, so all releases of Logto containing the connector‑saml component are potentially impacted until a fix is released.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact on the authentication process. The EPSS score is below 1% and Logto is not listed in the CISA KEV catalog, indicating a currently low probability of exploitation. Because the flaw concerns the validation of inbound SAML assertions, the attack vector is likely through a SAML identity provider that can supply crafted assertions to the Logto service. Once exploited, the attacker can replay assertions indefinitely, gaining persistent unauthorized access until the flaw is addressed or mitigated.
OpenCVE Enrichment