Skip to main content

iVerify

Type

Security review

Client

iVerify

Date

2026-06

Domain

AppSec

Effort

2 wks

Section

Technology Product Reviews

Trail of Bits's security review of iVerify (Jun 2026) identified 21 issues: 13 high, 5 medium, 2 low, and 1 informational.

Findings · 21

  1. 1 HTML injection in PDF generation enables SSRF and local file disclosure High
  2. 2 Unauthenticated HTTP endpoints expose scan data and report generation High
  3. 3 SQL injection vulnerability via unparameterized ClickHouse queries High
  4. 4 NoSQL injection vulnerability in report generation endpoint allows unauthorized access to scan data High
  5. 5 Outdated WebKit engine in wkhtmltopdf enables remote code execution High
  6. 6 Cryptographic secrets logged in decryption helper Medium
  7. 7 Hard-coded secrets and credentials in source code High
  8. 8 Unsafe tarfile extraction enables file write via path traversal attacks High
  9. 9 Server does not validate JWT signatures on OAuth ID tokens Informational
  10. 10 Remote code execution vulnerability due to use of eval() in sysdiagnose parsing High
  11. 11 Overprivileged Lambda IAM roles Medium
  12. 12 XXE injection in server SAML processing High
  13. 13 Archive extraction vulnerable to decompression bombs causing denial of service Medium
  14. 14 SCIM admin provisioning hard codes super admin role for new users Medium
  15. 15 SCIM user deprovisioning does not revoke admin principal or sessions Medium
  16. 16 Inconsistent session invalidation across admin operations Low
  17. 17 Encrypted SAML assertions bypass signature validation High
  18. 18 SAML assertion signatures are checked for presence but never cryptographically validated High
  19. 19 SAML signature validation does not verify that signatures reference their parent elements High
  20. 20 SAML response and assertion attributes are not validated High
  21. 21 File validation endpoint enables S3 file enumeration oracle Low

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related