The vendor explicitly identifies these products as affected by this CVE.
- Mendix SAML (Mendix 7 compatible)
- Mendix SAML (Mendix 8 compatible)
- Mendix SAML (Mendix 9 latest compatible, New Track)
- Mendix SAML (Mendix 9 latest compatible, Upgrade Track)
- Mendix SAML (Mendix 9.12/9.18 compatible, New Track)
- Mendix SAML (Mendix 9.12/9.18 compatible, Upgrade Track)
- Mendix SAML (Mendix 9.6 compatible, New Track)
- Mendix SAML (Mendix 9.6 compatible, Upgrade Track)
- Summary
- The affected versions of the module insufficiently verify the SAML assertions. This could allow unauthenticated remote attackers to bypass authentication and get access to the application. This CVE entry describes the incomplete fix for CVE-2023-25957 in a specific non default configuration.
- Remediation
- Update to V1.17.3 or later version
