CVE-2017-12870: Infoleak
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12870?
CVE-2017-12870 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2017-12870?
To fix CVE-2017-12870, upgrade SimpleSAMLphp to version 1.14.13 or later.
What versions of SimpleSAMLphp are affected by CVE-2017-12870?
CVE-2017-12870 affects SimpleSAMLphp versions 1.14.12 and earlier.
What type of attack does CVE-2017-12870 expose users to?
CVE-2017-12870 exposes users to man-in-the-middle attacks that can compromise session identifiers.
Does CVE-2017-12870 affect HTTPS service providers?
CVE-2017-12870 primarily affects non-HTTPS service providers, making it easier for attackers to intercept communications.