VDB
Sign up
MEDIUM5.9

GHSA-44pr-mgcp-v36r

SimpleSAMLphp Unauthenticated encryption in CBC mode

Quick fix

GHSA-44pr-mgcp-v36r — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp:^1.14.13

Details

SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp
Introduced in: 0Fixed in: 1.14.13
Fixcomposer require simplesamlphp/simplesamlphp:^1.14.13

References