Логотип exploitDog
bind:CVE-2025-27773
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-27773

Количество 4

Количество 4

ubuntu логотип

CVE-2025-27773

11 месяцев назад

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2025-27773

11 месяцев назад

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2025-27773

11 месяцев назад

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-46r4-f8gj-xg56

11 месяцев назад

The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-27773

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.

CVSS3: 8.6
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-27773

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.

CVSS3: 8.6
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-27773

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...

CVSS3: 8.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-46r4-f8gj-xg56

The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding

CVSS3: 8.6
0%
Низкий
11 месяцев назад

Уязвимостей на страницу