Impact
Casdoor versions 2.362.0 and earlier map captured SAML assertions directly to authenticated sessions without any replay protection. The ParseSamlResponse function accepts an assertion, extracts the user information, and immediately creates a session, overlooking whether the assertion has been used before. An attacker who has intercepted a valid SAML assertion can simply resend it to obtain a new authenticated session for the asserted subject, potentially including administrative accounts, and therefore gain full access without needing the user’s password or MFA tokens. This flaw constitutes a high‑impact session hijacking vulnerability that undermines authentication integrity and can lead to privilege escalation.
Affected Systems
The affected vendor is Casdoor, product Casdoor. All deployments running Casdoor 2.362.0 or earlier are vulnerable. No specific downstream product versions are listed beyond the primary product identifier.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw. Because the EPSS score is not available, the exact exploit probability is unknown, but the flaw can be leveraged simply by capturing any legitimate SAML assertion and replaying it, which is a relatively low‑effort attack vector. The vulnerability is not listed in the CISA KEV catalog, but its impact and lack of preventive controls warrant immediate attention.
OpenCVE Enrichment