HIGH7.5
GHSA-923w-2xv2-7pr8
SimpleSAMLphp Improper Verification of Cryptographic Signature
Quick fix
GHSA-923w-2xv2-7pr8 — simplesamlphp/saml2: upgrade to the fixed version with the command below.
composer require simplesamlphp/saml2:^1.10.5Details
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/saml2
Introduced in:
0Fixed in: 1.10.5Fix
composer require simplesamlphp/saml2:^1.10.5Packagist/simplesamlphp/saml2
Introduced in:
2.0Fixed in: 2.3.7Fix
composer require simplesamlphp/saml2:^2.3.7Packagist/simplesamlphp/saml2
Introduced in:
3.0Fixed in: 3.1.3Fix
composer require simplesamlphp/saml2:^3.1.3