Hall of Fame
Back to Hall of Fame Contents Back to WeKan Website

SamlReplayBleed

CVEIconVulnerability nameDate Responsible Security Disclosure byStarsProcessVulnerabilities
-

SamlReplayBleed 2026-09-27 xet7 Gold starGold starGold star Found and fixed during the sibling authentication audit; reproduced with locally signed SAML responses.

The SAML adapter inherited node-saml’s disabled InResponseTo validation. A still-valid signed response could be submitted again under a different RelayState. The adapter now requires a live request ID, and a bounded synchronous guard consumes each verified response before a login credential is stored, including concurrent validations.

CWE-294. High severity: reuse requires possession of a valid signed response. No CVE assigned. Unsolicited IdP-initiated responses are now rejected; login must start from WeKan.

Fix prepared for the Upcoming release.

Details

Attributable concurrent replay refusals are summarized as SamlReplayBleed in Admin Panel / Problems. The library also rejects unknown or expired request IDs; those failures cannot reliably distinguish replay from an ordinary stale login. State is process-local, so clustered login handshakes require sticky routing. The eight-hour consumption cache is bounded and fails closed at capacity.

Source fix and regression coverage

Compatibility correction, 2026-09-28

The application guard originally called an accessor absent from node-saml and consequently rejected valid logins. It now reads the validated profile.inResponseTo string while retaining request correlation and single-use consumption. ACS errors reach the sign-in page without exchanging a missing credential.

Response compatibility fix and signed-popup regression tests. Local Chromium tests establish a Meteor session through a signed SAML popup and verify a tampered response reports its real error. The reporter's external identity provider and deployment settings were not tested or changed.

Original verification

A generated test certificate and local protocol fixture reproduce the old configuration accepting the same signed response twice. The patched configuration accepts valid login once and rejects replay, unknown requests, unsigned and tampered responses. Atomic consumption, expiration and capacity are tested. This is not a live external identity-provider or full SAML browser deployment test.

The authentication regression run passed 46 focused Node suites and five Chromium scenarios. The local Meteor application rebuilt successfully. Live OpenLDAP/Active Directory, external CAS/SAML providers, Sandstorm and the FerretDB authentication matrix were not tested.

Authentication audit, findings and limitations