MEDIUM5.9
GHSA-44pr-mgcp-v36r
SimpleSAMLphp Unauthenticated encryption in CBC mode
Quick fix
GHSA-44pr-mgcp-v36r — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.
composer require simplesamlphp/simplesamlphp:^1.14.13Details
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/simplesamlphp
Introduced in:
0Fixed in: 1.14.13Fix
composer require simplesamlphp/simplesamlphp:^1.14.13References
- https://nvd.nist.gov/vuln/detail/CVE-2017-12870[ADVISORY]
- https://github.com/simplesamlphp/simplesamlphp/commit/4c939be1696bacb2b95ee11d4ebc5814a08b04c5[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/CVE-2017-12870.yaml[WEB]
- https://github.com/simplesamlphp/simplesamlphp[PACKAGE]
- https://simplesamlphp.org/security/201704-01[WEB]