OktaOKTA-1PL3DVL
SAML Attribute Smuggling Vulnerability Allowing User Impersonation in Passport-WS-Fed...
UnratedCVE-2025-46573 · Published May 6, 2025
This vulnerability allows an attacker to impersonate any user during SAML authentication by tampering with a valid SAML response in Passport-WS-Fed. Upgrade to v4.6.4 or greater.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
More Okta advisories
All Okta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 222025 | Okta On-Premises Provisioning (OPP) Password Reset Information Disclosure CVE-2025-7371... | Unrated | No fix yet |
| Jun 32025 | Deserialization of Untrusted Data in Auth0-PHP SDK CVE-2025-48951 - Jun 3, 2025 | Unrated | No fix yet |
| Jun 32025 | CDN Caching of Session Cookies in NextJS-Auth0 SDK CVE-2025-48947 - Jun 3, 2025 | Unrated | No fix yet |
| May 152025 | Brute Force Authentication Tags of CookieStore Sessions in Auth0-PHP SDK CVE-2025-47275... | Unrated | No fix yet |
| May 62025 | SAML Signature Wrapping Vulnerability Leading to User Impersonation in Passport-WS-Fed... | Unrated | No fix yet |
| Apr 302025 | JWT Invalid Signature Validation in Auth0 Account Linking Extensions CVE-2025-46345 - Apr... | Unrated | No fix yet |