Количество 4
Количество 4
CVE-2018-7644
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
CVE-2018-7644
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
CVE-2018-7644
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp b ...
GHSA-923w-2xv2-7pr8
SimpleSAMLphp Improper Verification of Cryptographic Signature
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-7644 The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue. | CVSS3: 7.5 | 0% Низкий | почти 8 лет назад | |
CVE-2018-7644 The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue. | CVSS3: 7.5 | 0% Низкий | почти 8 лет назад | |
CVE-2018-7644 The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp b ... | CVSS3: 7.5 | 0% Низкий | почти 8 лет назад | |
GHSA-923w-2xv2-7pr8 SimpleSAMLphp Improper Verification of Cryptographic Signature | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу