VDB
Sign up
HIGH7.5

GHSA-923w-2xv2-7pr8

SimpleSAMLphp Improper Verification of Cryptographic Signature

Quick fix

GHSA-923w-2xv2-7pr8 — simplesamlphp/saml2: upgrade to the fixed version with the command below.

composer require simplesamlphp/saml2:^1.10.5

Details

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/saml2
Introduced in: 0Fixed in: 1.10.5
Fixcomposer require simplesamlphp/saml2:^1.10.5
Packagist/simplesamlphp/saml2
Introduced in: 2.0Fixed in: 2.3.7
Fixcomposer require simplesamlphp/saml2:^2.3.7
Packagist/simplesamlphp/saml2
Introduced in: 3.0Fixed in: 3.1.3
Fixcomposer require simplesamlphp/saml2:^3.1.3

References