Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv5p-6wrc-79wg

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

SimpleSAMLphp Use of insecure connection charset (sqlauth module)

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.

Пакеты

Наименование

simplesamlphp/simplesamlphp

composer
Затронутые версииВерсия исправления

< 1.15.2

1.15.2

EPSS

Процентиль: 68%
0.00585
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
nvd
около 8 лет назад

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.

CVSS3: 9.8
debian
около 8 лет назад

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL ...

EPSS

Процентиль: 68%
0.00585
Низкий

9.8 Critical

CVSS3