important · Edge — SAML
A self-signed SAML response can impersonate any identity accepted by MojoX::Authentication.
Affects
MojoX::Authentication, a Perl authentication library used by Mojolicious applications for local and SAML2 login.
The parser lacked a configured trust anchor, so an attacker could sign an assertion naming the target account and have it checked against the certificate embedded in that response.
Detail and 2 sources
MojoX::Authentication 0.006 and later contain the fix.