MEDIUM5.9
GHSA-ww3w-592j-5qrw
SimpleSAMLphp Incorrect IV generation for encryption
Quick fix
GHSA-ww3w-592j-5qrw — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.
composer require simplesamlphp/simplesamlphp:^1.14.12Details
The aesEncrypt method in `lib/SimpleSAML/Utils/Crypto.php` in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/simplesamlphp
Introduced in:
1.14.0Fixed in: 1.14.12Fix
composer require simplesamlphp/simplesamlphp:^1.14.12References
- https://nvd.nist.gov/vuln/detail/CVE-2017-12871[ADVISORY]
- https://github.com/simplesamlphp/simplesamlphp/commit/77df6a932d46daa35e364925eb73a175010dc904[WEB]
- https://github.com/simplesamlphp/simplesamlphp/commit/ccf75981187aa88f7165abdb1b1965c0934acda0[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/CVE-2017-12871.yaml[WEB]
- https://github.com/simplesamlphp/simplesamlphp[PACKAGE]
- https://simplesamlphp.org/security/201703-02[WEB]