MEDIUM6.1
GHSA-2qfc-48v5-4w5h
SimpleSAMLphp Open redirection protection bypass
Quick fix
GHSA-2qfc-48v5-4w5h — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.
composer require simplesamlphp/simplesamlphp:^1.15.2Details
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/simplesamlphp
Introduced in:
0Fixed in: 1.15.2Fix
composer require simplesamlphp/simplesamlphp:^1.15.2References
- https://nvd.nist.gov/vuln/detail/CVE-2018-6520[ADVISORY]
- https://github.com/simplesamlphp/simplesamlphp/issues/1473[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/CVE-2018-6520.yaml[WEB]
- https://github.com/simplesamlphp/simplesamlphp[PACKAGE]
- https://simplesamlphp.org/security/201801-02[WEB]