First published: Mon Feb 26 2018(Updated: )
Incorrect signature validation
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/simplesamlphp/saml2 | <1.10.5>=2.0<2.3.7>=3.0<3.1.3 | |
debian/simplesamlphp | 1.16.3-1+deb10u2 1.16.3-1+deb10u1 1.19.0-1 1.19.7-1 | |
Simplesamlphp Simplesamlphp | <1.15.3 | |
composer/simplesamlphp/saml2 | >=3.0<3.1.3 | 3.1.3 |
composer/simplesamlphp/saml2 | >=2.0<2.3.7 | 2.3.7 |
composer/simplesamlphp/saml2 | <1.10.5 | 1.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7644 is a vulnerability that affects the XmlSecLibs library used in the saml2 library in SimpleSAMLphp before 1.15.3.
CVE-2018-7644 has a severity rating of 7.5 (high).
CVE-2018-7644 allows a remote attacker to create a crafted SAML assertion that appears to be valid, bypassing signature verification.
Versions of SimpleSAMLphp up to 1.15.3, as well as certain versions of the simplesamlphp package in Debian, are affected by CVE-2018-7644.
To fix CVE-2018-7644, you should update to SimpleSAMLphp version 1.15.3 or later, or install the appropriate patched version of the simplesamlphp package in Debian.