CVE-2017-18122
SimpleSAMLphp Signature validation bypass
8.1
HIGH
CVSS 3.1
EPSS 1.1%
描述
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signature of at least one of the assertions is valid. Attributes contained in all the assertions received will be merged and the entityID of the first assertion received will be used, allowing an attacker to impersonate any user of any IdP given an assertion signed by the targeted IdP.
如何修補 CVE-2017-18122
要修補 CVE-2017-18122,請將受影響套件升級到下列已修補版本。
- —升級至 1.15.0-1 或更新版本
- —升級至 1.14.17 或更新版本
CVE-2017-18122 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.15.0-1
- from 0, < 1.14.17
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |