CVE-2017-18122: High severity simplesamlphp vulnerability
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signature of at least one of the assertions is valid. Attributes contained in all the assertions received will be merged and the entityID of the first assertion received will be used, allowing an attacker to impersonate any user of any IdP given an assertion signed by the targeted IdP.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18122?
CVE-2017-18122 has been rated as a moderate severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2017-18122?
To fix CVE-2017-18122, upgrade SimpleSAMLphp to version 1.14.17 or later.
Which versions of SimpleSAMLphp are affected by CVE-2017-18122?
Versions of SimpleSAMLphp prior to 1.14.17 are affected by CVE-2017-18122.
Does CVE-2017-18122 affect only SimpleSAMLphp Service Providers using SAML 1.1?
Yes, CVE-2017-18122 specifically affects SimpleSAMLphp Service Providers that utilize SAML 1.1.
What kind of issue is addressed by CVE-2017-18122?
CVE-2017-18122 addresses a signature-validation bypass issue that can compromise the integrity of SAML responses.