The vendor explicitly identifies these products as affected by this CVE.
- Mendix SAML (Mendix 9.24 compatible)
- Mendix SAML (Mendix 10.12 compatible)
- Mendix SAML (Mendix 10.21 compatible)
- Summary
- Affected versions of the module insufficiently enforce signature validation and binding checks. This could allow unauthenticated remote attackers to hijack an account in specific SSO configurations.
- Remediation
- Update to V3.6.21 or later version
