VDB
Sign up
MEDIUM5.9

GHSA-ww3w-592j-5qrw

SimpleSAMLphp Incorrect IV generation for encryption

Quick fix

GHSA-ww3w-592j-5qrw — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.

composer require simplesamlphp/simplesamlphp:^1.14.12

Details

The aesEncrypt method in `lib/SimpleSAML/Utils/Crypto.php` in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/simplesamlphp
Introduced in: 1.14.0Fixed in: 1.14.12
Fixcomposer require simplesamlphp/simplesamlphp:^1.14.12

References