MEDIUM
GHSA-g48f-pgwh-wwxx
onelogin/php-saml signature wrapping attacks
Quick fix
GHSA-g48f-pgwh-wwxx — onelogin/php-saml: upgrade to the fixed version with the command below.
composer require onelogin/php-saml:^2.10.0Details
Vulnerability in onelogin/php-saml versions prior to 2.10.0 allows signature Wrapping attacks which may result in a malicious user gaining unauthorized access to a system.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/onelogin/php-saml
Introduced in:
0Fixed in: 2.10.0Fix
composer require onelogin/php-saml:^2.10.0