VDB
Sign up
CRITICAL9.8

GHSA-qv5p-6wrc-79wg

SimpleSAMLphp Use of insecure connection charset (sqlauth module)

Quick fix

GHSA-qv5p-6wrc-79wg — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp:^1.15.2

Details

The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp
Introduced in: 0Fixed in: 1.15.2
Fixcomposer require simplesamlphp/simplesamlphp:^1.15.2

References