Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12869

Опубликовано: 01 сент. 2017
Источник: debian
EPSS Низкий

Описание

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simplesamlphpfixed1.14.15-1package

Примечания

  • https://simplesamlphp.org/security/201704-02

  • Patch: https://github.com/simplesamlphp/simplesamlphp/commit/f1e485284dd428ab3cd9500c62e19c7c7234be9a

EPSS

Процентиль: 61%
0.00418
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

CVSS3: 7.5
nvd
больше 8 лет назад

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

CVSS3: 7.5
github
больше 3 лет назад

SimpleSAMLphp Authentication context bypass in the multiauth module

EPSS

Процентиль: 61%
0.00418
Низкий