CVE-2018-6519: High severity SimpleSAMLphp SAML2 vulnerability
Denial of Service in timestamp validation function
Other sources
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/simplesamlphpto a version that resolves this vulnerability.Fixed in 1.16.3-1+deb10u2Fixed in 1.16.3-1+deb10u1Fixed in 1.19.0-1Fixed in 1.19.7-1 - Upgrade
Upgrade
composer/simplesamlphp/saml2to a version that resolves this vulnerability.Fixed in 3.1.1 - Upgrade
Upgrade
composer/simplesamlphp/saml2to a version that resolves this vulnerability.Fixed in 2.3.5 - Upgrade
Upgrade
composer/simplesamlphp/saml2to a version that resolves this vulnerability.Fixed in 1.10.4
Event History
Frequently Asked Questions
What is CVE-2018-6519?
CVE-2018-6519 is a vulnerability in the timestamp validation function of the SAML2 library in SimpleSAMLphp.
What is the severity of CVE-2018-6519?
The severity of CVE-2018-6519 is high with a CVSS score of 7.5.
How does CVE-2018-6519 affect SimpleSAMLphp?
CVE-2018-6519 affects SimpleSAMLphp versions before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1.
How can I fix CVE-2018-6519 in SimpleSAMLphp?
To fix CVE-2018-6519, upgrade SimpleSAMLphp to version 1.10.4 or higher for versions 1.x, version 2.3.5 or higher for versions 2.x, and version 3.1.1 or higher for versions 3.x.
Where can I find more information about CVE-2018-6519?
You can find more information about CVE-2018-6519 at the following references: [link1], [link2], [link3].