Skip to content

Conversation

@cjbarth
Copy link
Collaborator

@cjbarth cjbarth commented Apr 11, 2023

Description

node-saml has been updated with a patch release to address a security concern. Set the minimum allowed version of node-saml to make sure we get that security patch.

@cjbarth cjbarth added dependencies Pull requests that update a dependency file security labels Apr 11, 2023
@cjbarth cjbarth merged commit eb65615 into node-saml:master Apr 11, 2023
@cjbarth cjbarth deleted the security-update branch April 11, 2023 22:50
@markstos
Copy link
Contributor

markstos commented Apr 12, 2023

For those looking for the vuln details:

I'm not sure if these vulns are accessible through passport-saml or not, but considering that we pass through XML to be parsed by these libraries, it's best to presume that they are reachable through passport-saml.

AlbertPangilinan pushed a commit to Foxquilt/foxden-saml-passport that referenced this pull request Sep 24, 2025
Eric-G-Ji pushed a commit to Foxquilt/foxden-saml-passport that referenced this pull request Sep 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants