CVE-2017-12868: Critical severity simplesamlphp vulnerability
Session fixation and authentication bypass (authcrypt module)
Other sources
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12868?
CVE-2017-12868 is classified as a medium severity vulnerability due to its potential to allow session fixation and authentication bypass.
How do I fix CVE-2017-12868?
To fix CVE-2017-12868, upgrade SimpleSAMLphp to version 1.14.14 or later.
Which versions of SimpleSAMLphp are affected by CVE-2017-12868?
CVE-2017-12868 affects SimpleSAMLphp versions 1.14.12 up to 1.14.13.
What type of attacks can CVE-2017-12868 facilitate?
CVE-2017-12868 can facilitate session fixation attacks and potential authentication bypass.
Which PHP versions does CVE-2017-12868 impact?
CVE-2017-12868 impacts PHP versions before 5.6, specifically when used with SimpleSAMLphp versions prior to 1.14.14.