CVE-2018-7644: High severity SimpleSAMLphp vulnerability
Incorrect signature validation
Other sources
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/simplesamlphpto a version that resolves this vulnerability.Fixed in 1.16.3-1+deb10u2Fixed in 1.16.3-1+deb10u1Fixed in 1.19.0-1Fixed in 1.19.7-1 - Upgrade
Upgrade
composer/simplesamlphp/saml2to a version that resolves this vulnerability.Fixed in 3.1.3 - Upgrade
Upgrade
composer/simplesamlphp/saml2to a version that resolves this vulnerability.Fixed in 2.3.7 - Upgrade
Upgrade
composer/simplesamlphp/saml2to a version that resolves this vulnerability.Fixed in 1.10.5
Event History
Frequently Asked Questions
What is CVE-2018-7644?
CVE-2018-7644 is a vulnerability that affects the XmlSecLibs library used in the saml2 library in SimpleSAMLphp before 1.15.3.
What is the severity of CVE-2018-7644?
CVE-2018-7644 has a severity rating of 7.5 (high).
How does CVE-2018-7644 work?
CVE-2018-7644 allows a remote attacker to create a crafted SAML assertion that appears to be valid, bypassing signature verification.
Which software versions are affected by CVE-2018-7644?
Versions of SimpleSAMLphp up to 1.15.3, as well as certain versions of the simplesamlphp package in Debian, are affected by CVE-2018-7644.
How can I fix CVE-2018-7644?
To fix CVE-2018-7644, you should update to SimpleSAMLphp version 1.15.3 or later, or install the appropriate patched version of the simplesamlphp package in Debian.