SAMLStorm: Critical Authentication Bypass Vulnerabilities

Incident Report for BigID

Resolved

The BigID Product Security Incident Response Team (PSIRT) was alerted to two (2) critical vulnerabilities known as SAMLStorm. These vulnerabilities affect the xml-crypto Node.js library (v6.0.0 and earlier, CVE-2025-29775 & CVE-2025-29774). If exploited, these vulnerabilities could result in full account takeovers, including admin accounts, in affected applications with no user interaction. BigID leverages these libraries to perform SAML response validations. The exploitation of these vulnerabilities depends on the IdP configuration for each BigID tenant. Customers who are leveraging BigID Cloud have already implemented a patch. For customers who are on-premise, BigID highly advises that you upgrade to release-222.18, release-218.76, release-211.74, release-205.116, release-198.93. While there is no public proof-of-concept available, BigID Product and Cloud Security teams are continuing to monitor and address the issue and will provide appropriate updates accordingly.
https://bigid.com/bigid-security-bulletins/
Posted Mar 17, 2025 - 13:09 UTC