Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j96g-47x2-46hv

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

SimpleSAMLphp Session fixation issue and authentication bypass in the authcrypt module

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

Пакеты

Наименование

simplesamlphp/simplesamlphp

composer
Затронутые версииВерсия исправления

>= 1.14.12, < 1.14.14

1.14.14

EPSS

Процентиль: 72%
0.00764
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
nvd
почти 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
debian
почти 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...

EPSS

Процентиль: 72%
0.00764
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-384