HIGH7.5
GHSA-fj28-869x-vv5g
SimpleSAMLphp InfoCard module Incorrect signature verification
Quick fix
GHSA-fj28-869x-vv5g — simplesamlphp/simplesamlphp-module-infocard: upgrade to the fixed version with the command below.
composer require simplesamlphp/simplesamlphp-module-infocard:^1.0.1Details
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/simplesamlphp-module-infocard
Introduced in:
0Fixed in: 1.0.1Fix
composer require simplesamlphp/simplesamlphp-module-infocard:^1.0.1References
- https://nvd.nist.gov/vuln/detail/CVE-2017-12874[ADVISORY]
- https://github.com/simplesamlphp/simplesamlphp-module-infocard/commit/63b84cc837ea62bf87f4bf4af29b4420f49311a9[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp-module-infocard/CVE-2017-12874.yaml[WEB]
- https://github.com/simplesamlphp/simplesamlphp[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html[WEB]
- https://simplesamlphp.org/security/201612-03[WEB]
- https://www.debian.org/security/2018/dsa-4127[WEB]