GHSA-6gc6-m364-85ww

Suggest an improvement
Source
https://github.com/advisories/GHSA-6gc6-m364-85ww
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-6gc6-m364-85ww/GHSA-6gc6-m364-85ww.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6gc6-m364-85ww
Aliases
Published
2020-01-24T21:26:13Z
Modified
2023-11-08T04:03:51.862218Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Log injection in SimpleSAMLphp
Details

Background

SimpleSAMLphp has a logging functionality that allows system administrators to keep track of the activity, errors, and statistics. Additionally, it allows users to report errors, shall they happen. An error report contains a report identifier, which is logged once submitted.

Description

The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, didn't properly sanitize the report identifier obtained from the request. This allows an attacker, under specific circumstances, to inject new log lines by manually crafting this report ID.

When configured to use the file logging handler, SimpleSAMLphp will output all its logs by appending each log line to a given file. Since the reportID parameter received in a request sent to www/errorreport.php was not properly sanitized, it was possible to inject newline characters into it, effectively allowing a malicious user to inject new log lines with arbitrary content.

Affected versions

SimpleSAMLphp versions up to 1.18.3.

Impact

An attacker may use this issue to inject logs messages into a SimpleSAMLphp log file, trying to trick or confuse system administrators. However, the attack surface is considered small, as the attack will only work with the file logging handler, which opens the log file in append-only mode. This means an attacker cannot edit or remove existing log messages, and even if non-ascii characters are written to the log, the file will always be readable with a simple text editor.

Resolution

Upgrade the SimpleSAMLphp installation to version 1.18.4.

Credit

This vulnerability was discovered and reported by Frederic Vleminckx on January 23, 2020.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2020-01-24T20:46:16Z",
    "severity": "LOW",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-532"
    ]
}
References

Affected packages

Packagist / simplesamlphp/simplesamlphp

Package

Name
simplesamlphp/simplesamlphp
Purl
pkg:composer/simplesamlphp/simplesamlphp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.18.4

Affected versions

v1.*

v1.12.0
v1.13.0-rc1
v1.13.0-rc2
v1.13.0
v1.13.1
v1.13.2
v1.14.0-rc1
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.14.7
v1.14.8
v1.14.9
v1.14.10
v1.14.11
v1.14.12
v1.14.13
v1.14.14
v1.14.15
v1.14.16
v1.14.17
v1.15.0-rc1
v1.15.0-rc2
v1.15.0-rc3
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.17.0-rc1
v1.17.0-rc2
v1.17.0-rc3
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.17.5
v1.17.6
v1.17.7
v1.17.8
v1.18.0-rc1
v1.18.0-rc2
v1.18.0
v1.18.1
v1.18.2
v1.18.3

1.*

1.16.0-rc1
1.16.0
1.16.1
1.16.2
1.16.3