CVE-2017-12873

CRITICAL9.8EPSS 0.73%

Incorrect persistent NameID generation in SimpleSAMLphp

Published: 1/24/2020Modified: 4/28/2026
Also known as:GHSA-gp2m-7cfp-h6gfDEBIAN-CVE-2017-12873

Description

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (8)