Логотип exploitDog
bind:CVE-2018-7711
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-7711

Количество 4

Количество 4

ubuntu логотип

CVE-2018-7711

почти 8 лет назад

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true boolean value.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2018-7711

почти 8 лет назад

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true boolean value.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2018-7711

почти 8 лет назад

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 h ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-g888-g2pp-82hf

больше 3 лет назад

SimpleSAMLphp saml2 incorrect signature validation

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-7711

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true boolean value.

CVSS3: 8.1
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-7711

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true boolean value.

CVSS3: 8.1
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-7711

HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 h ...

CVSS3: 8.1
0%
Низкий
почти 8 лет назад
github логотип
GHSA-g888-g2pp-82hf

SimpleSAMLphp saml2 incorrect signature validation

CVSS3: 8.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу