CVE-2017-12869: Input Validation
Authentication context bypass (multiauth module)
Other sources
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12869?
CVE-2017-12869 is classified as a medium severity vulnerability due to authentication context bypass risks.
How do I fix CVE-2017-12869?
To fix CVE-2017-12869, upgrade SimpleSAMLphp to version 1.14.14 or later.
Which versions of SimpleSAMLphp are affected by CVE-2017-12869?
CVE-2017-12869 affects SimpleSAMLphp versions up to and including 1.14.13.
What is the impact of CVE-2017-12869?
The impact of CVE-2017-12869 allows remote attackers to bypass authentication context restrictions.
Is CVE-2017-12869 specific to any operating system?
CVE-2017-12869 is not specific to any operating system but affects installations of SimpleSAMLphp across different platforms.