GHSA-5fj7-f8x3-q2mc

Suggest an improvement
Source
https://github.com/advisories/GHSA-5fj7-f8x3-q2mc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-5fj7-f8x3-q2mc/GHSA-5fj7-f8x3-q2mc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5fj7-f8x3-q2mc
Aliases
Published
2022-04-22T00:24:09Z
Modified
2024-01-12T23:26:48Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
simpleSAMLphp incorrectly handles XML encryption
Details

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Database specific
{
    "cwe_ids":  [
        "CWE-755"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-01-12T23:10:19Z",
    "nvd_published_at":  "2019-11-06T15:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Packagist / simplesamlphp/simplesamlphp

Package

Name
simplesamlphp/simplesamlphp
Purl
pkg:composer/simplesamlphp/simplesamlphp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-5fj7-f8x3-q2mc/GHSA-5fj7-f8x3-q2mc.json"