Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-7644

Опубликовано: 05 мар. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:simplesamlphp:simplesamlphp:*:*:*:*:*:*:*:*
Версия до 1.15.3 (исключая)

EPSS

Процентиль: 38%
0.00166
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

CVSS3: 7.5
debian
почти 8 лет назад

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp b ...

CVSS3: 7.5
github
больше 3 лет назад

SimpleSAMLphp Improper Verification of Cryptographic Signature

EPSS

Процентиль: 38%
0.00166
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-347