Impact
The vulnerability arises from improper verification of a cryptographic signature in Apache APISIX’s saml-auth plugin. Because the default configuration fails to validate the SAML response, an attacker who can provide a crafted request can impersonate any user on all routes protected by the plugin without needing valid credentials. This allows the attacker to act with full privileges of the impersonated user, compromising confidentiality and integrity of protected data.
Affected Systems
Apache Software Foundation: Apache APISIX is impacted for all releases from 3.17.0 through 3.18.0 when the saml-auth plugin is enabled using its default configuration. No other products or versions are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate to high severity vulnerability. The EPSS score is not available, and the risk is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is unclear; however, the flaw requires no authentication and a simple crafted request, making it easily exploitable in environments where the plugin is enabled. Attackers can leverage this flaw to impersonate users and carry out any action permitted to those users on every protected route.
OpenCVE Enrichment