The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.14.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.6"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.7"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.8"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.9"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.14.11"
}
]
}