VDB
Sign up
HIGH7.5

GHSA-hhm8-2j4g-mpgg

SimpleSAMLphp SAML2 library Regular Expression Denial of Service vulnerability

Quick fix

GHSA-hhm8-2j4g-mpgg — simplesamlphp/saml2: upgrade to the fixed version with the command below.

composer require simplesamlphp/saml2:^1.10.4

Details

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/saml2
Introduced in: 0Fixed in: 1.10.4
Fixcomposer require simplesamlphp/saml2:^1.10.4
Packagist/simplesamlphp/saml2
Introduced in: 2.0Fixed in: 2.3.5
Fixcomposer require simplesamlphp/saml2:^2.3.5
Packagist/simplesamlphp/saml2
Introduced in: 3.0Fixed in: 3.1.1
Fixcomposer require simplesamlphp/saml2:^3.1.1

References