GHSA-923w-2xv2-7pr8
Dashboard / Vulnerabilities / GHSA-923w-2xv2-7pr8
Summary: SimpleSAMLphp Improper Verification of Cryptographic Signature
Details: The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-7644, https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/saml2/CVE-2018-7644.yaml, https://github.com/simplesamlphp/simplesamlphp, https://simplesamlphp.org/security/201802-01
Affected packages
Package
Name: simplesamlphp/saml2
Purl: pkg:composer/simplesamlphp/saml2
Affected ranges
Type: ECOSYSTEM
Events:
