HIGH7.5
GHSA-hhm8-2j4g-mpgg
SimpleSAMLphp SAML2 library Regular Expression Denial of Service vulnerability
Quick fix
GHSA-hhm8-2j4g-mpgg — simplesamlphp/saml2: upgrade to the fixed version with the command below.
composer require simplesamlphp/saml2:^1.10.4Details
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/saml2
Introduced in:
0Fixed in: 1.10.4Fix
composer require simplesamlphp/saml2:^1.10.4Packagist/simplesamlphp/saml2
Introduced in:
2.0Fixed in: 2.3.5Fix
composer require simplesamlphp/saml2:^2.3.5Packagist/simplesamlphp/saml2
Introduced in:
3.0Fixed in: 3.1.1Fix
composer require simplesamlphp/saml2:^3.1.1References
- https://nvd.nist.gov/vuln/detail/CVE-2018-6519[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/saml2/CVE-2018-6519.yaml[WEB]
- https://github.com/simplesamlphp/simplesamlphp[PACKAGE]
- https://simplesamlphp.org/security/201801-01[WEB]
- https://www.debian.org/security/2018/dsa-4127[WEB]