Description
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1314-1 | simplesamlphp security update |
EUVD |
EUVD-2022-3265 | The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue. |
Github GHSA |
GHSA-923w-2xv2-7pr8 | SimpleSAMLphp Improper Verification of Cryptographic Signature |
References
| Link | Providers |
|---|---|
| https://simplesamlphp.org/security/201802-01 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:31:05.114Z
Reserved: 2018-03-02T00:00:00.000Z
Link: CVE-2018-7644
No data.
Status : Modified
Published: 2018-03-05T14:29:00.377
Modified: 2024-11-21T04:12:28.083
Link: CVE-2018-7644
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA