Security Advisory

CVE-2024-25718

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-02-11 00:00:00
Last updated 2025-04-24 15:45:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.