CVE detail
CVE-2020-5407 — CVE-2020-5407
Published 2020-05-13 · Modified 2026-06-17 · Vendor pivotal_software · Product spring_security · Source nvd
HIGH
severity
CVSS-derived band
0.0120
EPSS probability
exploitation probability, 30d
65.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion that Spring Security will accept as valid.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References