VDB
Sign up
MEDIUM

GHSA-g48f-pgwh-wwxx

onelogin/php-saml signature wrapping attacks

Quick fix

GHSA-g48f-pgwh-wwxx — onelogin/php-saml: upgrade to the fixed version with the command below.

composer require onelogin/php-saml:^2.10.0

Details

Vulnerability in onelogin/php-saml versions prior to 2.10.0 allows signature Wrapping attacks which may result in a malicious user gaining unauthorized access to a system.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/onelogin/php-saml
Introduced in: 0Fixed in: 2.10.0
Fixcomposer require onelogin/php-saml:^2.10.0

References