VDB
Sign up
HIGH7.5

GHSA-qc43-78vj-vg7p

SimpleSAMLphp Authentication context bypass in the multiauth module

Quick fix

GHSA-qc43-78vj-vg7p — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp:^1.14.14

Details

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp
Introduced in: 0Fixed in: 1.14.14
Fixcomposer require simplesamlphp/simplesamlphp:^1.14.14

References