CVE-2025-24894
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-24894 affects SPID.AspNetCore.Authentication, an AspNetCore Remote Authenticator for SPID. This vulnerability lies in the SAML2 standard used for authentication and authorization, where an attacker can inject an unsigned XML element into a signed SAML response, bypassing the validation logic. Since there's no guarantee that the first signature refers to the root object, all subsequent signatures will be considered valid. An attacker can use this vulnerability to create arbitrary SAML responses, impersonating any SPID and/or CIE user. Version 3.4.0 of the SDK addresses this issue, and upgrading is advised as there are no known workarounds.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.