GHSA-j5g2-q29x-cw3h

Suggest an improvement
Source
https://github.com/advisories/GHSA-j5g2-q29x-cw3h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j5g2-q29x-cw3h
Withdrawn
2024-12-04T16:13:50Z
Published
2024-12-02T20:00:29Z
Modified
2024-12-04T16:25:46Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
Summary
SimpleSAMLphp vulnerable to XXE in parsing SAML messages
Details

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability affects users of the SimpleSAMLphp tarball, not the SimpleSAMLphp Composer package. The underlying information about CVE-2024-52596 is still valid.

Original Description

Summary

When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE.

Mitigation:

Remove the LIBXML_DTDLOAD | LIBXML_DTDATTR options from $options is in: https://github.com/simplesamlphp/saml2/blob/717c0adc4877ebd58428637e5626345e59fa0109/src/SAML2/DOMDocumentFactory.php#L41

Background / details

To be published on Dec 8th

Database specific
{
    "cwe_ids":  [
        "CWE-611"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-12-02T20:00:29Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

Packagist
simplesamlphp/simplesamlphp

Package

Name
simplesamlphp/simplesamlphp
Purl
pkg:composer/simplesamlphp/simplesamlphp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3.0
Fixed
2.3.4

Affected versions

v2.*
v2.3.0
v2.3.1
v2.3.2
v2.3.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"
simplesamlphp/simplesamlphp

Package

Name
simplesamlphp/simplesamlphp
Purl
pkg:composer/simplesamlphp/simplesamlphp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2.0
Fixed
2.2.4

Affected versions

v2.*
v2.2.0
v2.2.1
v2.2.2
v2.2.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"
simplesamlphp/simplesamlphp

Package

Name
simplesamlphp/simplesamlphp
Purl
pkg:composer/simplesamlphp/simplesamlphp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Fixed
2.1.7

Affected versions

2.*
2.1.0
v2.*
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"
simplesamlphp/simplesamlphp

Package

Name
simplesamlphp/simplesamlphp
Purl
pkg:composer/simplesamlphp/simplesamlphp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.15

Affected versions

v1.*
v1.12.0
v1.13.0-rc1
v1.13.0-rc2
v1.13.0
v1.13.1
v1.13.2
v1.14.0-rc1
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.14.7
v1.14.8
v1.14.9
v1.14.10
v1.14.11
v1.14.12
v1.14.13
v1.14.14
v1.14.15
v1.14.16
v1.14.17
v1.15.0-rc1
v1.15.0-rc2
v1.15.0-rc3
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.17.0-rc1
v1.17.0-rc2
v1.17.0-rc3
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.17.5
v1.17.6
v1.17.7
v1.17.8
v1.18.0-rc1
v1.18.0-rc2
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.18.4
v1.18.5
v1.18.6
v1.18.7
v1.18.8
v1.19.0-rc1
v1.19.0
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.19.5
v1.19.6
v1.19.7
1.*
1.16.0-rc1
1.16.0
1.16.1
1.16.2
1.16.3
1.19.8
1.19.9
v2.*
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.11
v2.0.0-beta99
v2.0.0-rc1
v2.0.0-rc2
v2.0.0-rc3
v2.0.0
v2.0.1
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.0.10
v2.0.11
v2.0.12
v2.0.13
v2.0.14
2.*
2.0.2
2.0.3
2.0.4-alpha.1
2.0.4
2.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"