Full Changelog: https://github.com/litesaml/lightsaml/compare/5.0.1...5.1.0
LightSAML 5.0.0 was vulnerable to an XML Signature Wrapping (XSW) attack allowing an attacker who has captured one genuine signed assertion to have LightSAML accept a fully attacker-authored assertion as IdP-signed, leading to authentication bypass and privilege escalation.
The fix enforces two invariants before signature validation: the ds:Signature
parent element must carry the ID referenced by the fragment URI, and that ID
must be unique in the document.
Full Changelog: https://github.com/litesaml/lightsaml/compare/5.0.0...5.0.1
Full Changelog: https://github.com/litesaml/lightsaml/compare/4.7.0...5.0.0
Full Changelog: https://github.com/litesaml/lightsaml/compare/4.6.1...4.7.0
How can I help you explore Laravel packages today?