VDB
Sign up
MEDIUM4.7

GHSA-cvrm-5hp6-h523

SimpleSAMLphp casserver: Open Redirect in logout

Quick fix

GHSA-cvrm-5hp6-h523 — simplesamlphp/simplesamlphp-module-casserver: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp-module-casserver:^7.0.0

Details

### Summary

The logout endpoint accepts a `url` query parameter to redirect to. casserver treats that url as trusted, and either (depending on configuration) redirects the browser there, or shows a "you've been logged out" page with a link to continue to that url.

There are a number of other things broken with logout in 7 (cas v3 uses a different query parameters, etc)

### Details

https://github.com/simplesamlphp/simplesamlphp-module-casserver/blob/21418f7efbea8c4f078fd4a7d1b9eacf94dd4941/src/Controller/LogoutController.php#L104

Previous module checked the url against the valid service urls.

### PoC

The docker instructions from the README.md run an image with a vulnerable config.

Accessing https://localhost/cas/logout?url=https://google.com will redirect to Google

### Impact

Impacted configs have

```php 'enable_logout' => true, ```

and are most impacted if they also have

``` 'skip_logout_page' -> true, ```

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp-module-casserver
Introduced in: 7.0.0-rc1Fixed in: 7.0.0
Fixcomposer require simplesamlphp/simplesamlphp-module-casserver:^7.0.0
Packagist/simplesamlphp/simplesamlphp-module-casserver
Introduced in: 0Fixed in: 6.3.1
Fixcomposer require simplesamlphp/simplesamlphp-module-casserver:^6.3.1

References