Audit Open Original ↗
iVerify
Type
Security review
Client
iVerify
Date
2026-06
Domain
AppSec
Effort
2 wks
Section
Technology Product Reviews
Trail of Bits's security review of iVerify (Jun 2026) identified 21 issues: 13 high, 5 medium, 2 low, and 1 informational.
Findings · 21
- 1 HTML injection in PDF generation enables SSRF and local file disclosure High
- 2 Unauthenticated HTTP endpoints expose scan data and report generation High
- 3 SQL injection vulnerability via unparameterized ClickHouse queries High
- 4 NoSQL injection vulnerability in report generation endpoint allows unauthorized access to scan data High
- 5 Outdated WebKit engine in wkhtmltopdf enables remote code execution High
- 6 Cryptographic secrets logged in decryption helper Medium
- 7 Hard-coded secrets and credentials in source code High
- 8 Unsafe tarfile extraction enables file write via path traversal attacks High
- 9 Server does not validate JWT signatures on OAuth ID tokens Informational
- 10 Remote code execution vulnerability due to use of eval() in sysdiagnose parsing High
- 11 Overprivileged Lambda IAM roles Medium
- 12 XXE injection in server SAML processing High
- 13 Archive extraction vulnerable to decompression bombs causing denial of service Medium
- 14 SCIM admin provisioning hard codes super admin role for new users Medium
- 15 SCIM user deprovisioning does not revoke admin principal or sessions Medium
- 16 Inconsistent session invalidation across admin operations Low
- 17 Encrypted SAML assertions bypass signature validation High
- 18 SAML assertion signatures are checked for presence but never cryptographically validated High
- 19 SAML signature validation does not verify that signatures reference their parent elements High
- 20 SAML response and assertion attributes are not validated High
- 21 File validation endpoint enables S3 file enumeration oracle Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related