VDB
Sign up
MEDIUM6.1

GHSA-2qfc-48v5-4w5h

SimpleSAMLphp Open redirection protection bypass

Quick fix

GHSA-2qfc-48v5-4w5h — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp:^1.15.2

Details

SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp
Introduced in: 0Fixed in: 1.15.2
Fixcomposer require simplesamlphp/simplesamlphp:^1.15.2

References