Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7644

Опубликовано: 05 мар. 2018
Источник: debian
EPSS Низкий

Описание

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simplesamlphpfixed1.15.3-1package

Примечания

  • https://simplesamlphp.org/security/201802-01

  • Fixed by: https://github.com/simplesamlphp/saml2/commit/88a9ae848c4b310b1c53b5700893d890999dd930

EPSS

Процентиль: 38%
0.00166
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

CVSS3: 7.5
nvd
почти 8 лет назад

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

CVSS3: 7.5
github
больше 3 лет назад

SimpleSAMLphp Improper Verification of Cryptographic Signature

EPSS

Процентиль: 38%
0.00166
Низкий