Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc43-78vj-vg7p

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

SimpleSAMLphp Authentication context bypass in the multiauth module

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

Пакеты

Наименование

simplesamlphp/simplesamlphp

composer
Затронутые версииВерсия исправления

< 1.14.14

1.14.14

EPSS

Процентиль: 83%
0.02348
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

CVSS3: 7.5
nvd
около 9 лет назад

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

CVSS3: 7.5
debian
около 9 лет назад

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remot ...

EPSS

Процентиль: 83%
0.02348
Низкий

7.5 High

CVSS3

Дефекты

CWE-20