Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6929-8p9f-26jx

Опубликовано: 02 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass

Summary

SimpleSAMLphp's HTTP-Artifact receive path can treat an unsigned embedded SAML Response as cryptographically valid for the wrong IdP.

In the HTTPArtifact::receive() flow, the SOAP ArtifactResponse receives a TLS-based validator from SOAPClient::addSSLValidator(). The embedded SAML Response then receives a validator that delegates signature validation to that outer ArtifactResponse. Later, the SP validates the embedded Response against metadata selected from the embedded response issuer, not necessarily the artifact issuer.

The critical issue is that SOAPClient::validateSSL() returns normally when the TLS public key does not match the key currently being validated. SAML2\Message::validate() treats any validator call that does not throw an exception as successful. As a result, an ArtifactResponse obtained from one IdP can validate an unsigned embedded SAML Response that claims to be issued by a different IdP.

In a multi-IdP/federation deployment where a malicious or lower-trust IdP can issue an HTTP-Artifact response to an SP, this can allow the attacker to authenticate to the SP as arbitrary users from a higher-trust victim IdP.

Impact

A malicious or lower-trust IdP in the same SP/federation trust set can authenticate to the SP as users from another IdP when HTTP-Artifact is used. The attacker can choose assertion attributes, NameID, and session data in the forged unsigned assertion.

This is an authentication bypass and identity-provider impersonation issue. In realistic federations, the security boundary between IdPs matters: a compromised or low-assurance IdP should not be able to mint identities for a high-assurance IdP.

Пакеты

Наименование

simplesamlphp/saml2

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.2.1

6.2.1

Наименование

simplesamlphp/saml2

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.6

5.0.6

Наименование

simplesamlphp/saml2

composer
Затронутые версииВерсия исправления

>= 4.20.0, < 4.20.2

4.20.2

Наименование

simplesamlphp/saml2-legacy

composer
Затронутые версииВерсия исправления

>= 4.20.0, < 4.20.2

4.20.2

Наименование

simplesamlphp/saml2

composer
Затронутые версииВерсия исправления

< 4.19.3

4.19.3

Наименование

simplesamlphp/saml2-legacy

composer
Затронутые версииВерсия исправления

< 4.19.3

4.19.3

EPSS

Процентиль: 27%
0.00344
Низкий

8.7 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.7
ubuntu
19 дней назад

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a TLS-based validator to the outer SOAP ArtifactResponse, while the embedded Response receives a validator that delegates to the outer message and is later checked against metadata selected from the embedded response issuer rather than necessarily the artifact issuer. SOAPClient::validateSSL() returns normally when the TLS public key does not match the key being validated, and SAML2\Message::validate() treats a validator call that does not throw as successful. In a multi-IdP federation, a malicious or lower-trust IdP can therefore provide an ArtifactResponse containing an unsigned Response that claims a higher-trust victim IdP as issuer and authenticate as arbitrary users with ...

CVSS3: 8.7
nvd
19 дней назад

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator() attaches a TLS-based validator to the outer SOAP ArtifactResponse, while the embedded Response receives a validator that delegates to the outer message and is later checked against metadata selected from the embedded response issuer rather than necessarily the artifact issuer. SOAPClient::validateSSL() returns normally when the TLS public key does not match the key being validated, and SAML2\Message::validate() treats a validator call that does not throw as successful. In a multi-IdP federation, a malicious or lower-trust IdP can therefore provide an ArtifactResponse containing an unsigned Response that claims a higher-trust victim IdP as issuer and authenticate as arbitrary users with att

CVSS3: 8.7
debian
19 дней назад

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...

EPSS

Процентиль: 27%
0.00344
Низкий

8.7 High

CVSS3

Дефекты

CWE-295