GHSA-fj28-869x-vv5g

Suggest an improvement
Source
https://github.com/advisories/GHSA-fj28-869x-vv5g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-fj28-869x-vv5g/GHSA-fj28-869x-vv5g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fj28-869x-vv5g
Aliases
Published
2022-05-14T01:05:32Z
Modified
2024-04-25T21:26:44.871062Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
SimpleSAMLphp InfoCard module Incorrect signature verification
Details

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

Database specific
{
    "nvd_published_at": "2017-09-01T21:29:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-04-25T21:00:25Z"
}
References

Affected packages

Packagist / simplesamlphp/simplesamlphp-module-infocard

Package

Name
simplesamlphp/simplesamlphp-module-infocard
Purl
pkg:composer/simplesamlphp/simplesamlphp-module-infocard

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1

Affected versions

v1.*

v1.0