VDB
Sign up
HIGH7.5

GHSA-ww7x-3gxh-qm6r

Validation of SignedInfo

Quick fix

GHSA-ww7x-3gxh-qm6r — simplesamlphp/xml-security: upgrade to the fixed version with the command below.

composer require simplesamlphp/xml-security:^1.6.12

Details

Validation of an XML Signature requires verification that the hash value of the related XML-document (after any optional transformations and/or normalizations) matches a specific DigestValue-value, but also that the cryptografic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key.

Within the simpleSAMLphp/xml-security library (https://github.com/simplesamlphp/xml-security), the hash is being validated using SignedElementTrait::validateReference, and the signature is being verified in SignedElementTrait::verifyInternal

https://github.com/simplesamlphp/xml-security/blob/master/src/XML/SignedElementTrait.php:

![afbeelding](https://user-images.githubusercontent.com/841045/285817284-a7b7b3b4-768a-46e8-a34b-61790b6e23a5.png)

What stands out is that the signature is being calculated over the canonical version of the SignedInfo-tree. The validateReference method, however, uses the original non-canonicalized version of SignedInfo.

### Impact If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be potentially be possible to forge the signature. No possibilities to exploit this were found during the investigation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simplesamlphp/xml-security
Introduced in: 1.6.11Fixed in: 1.6.12
Fixcomposer require simplesamlphp/xml-security:^1.6.12
Packagist/simplesamlphp/saml2
Introduced in: 5.0.0-alpha.12Fixed in: 5.0.0-alpha.13
Fixcomposer require simplesamlphp/saml2:^5.0.0-alpha.13

References