VDB
Sign up
MEDIUM5.9

GHSA-v882-949x-6v28

SimpleSAMLphp allows timing side-channel attacks

Quick fix

GHSA-v882-949x-6v28 — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp:^1.15.0-rc1

Details

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp
Introduced in: 0Fixed in: 1.15.0-rc1
Fixcomposer require simplesamlphp/simplesamlphp:^1.15.0-rc1

References