CVE-2019-18632: Critical severity europa eidas-node integration package vulnerability
European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18632?
CVE-2019-18632 is rated as a high-severity vulnerability due to its potential for attackers to forge certificates.
How do I fix CVE-2019-18632?
To fix CVE-2019-18632, upgrade the European Commission eIDAS-Node Integration Package to version 2.3.1 or later.
What impact does CVE-2019-18632 have on organizations?
CVE-2019-18632 allows attackers to impersonate legitimate entities by using forged certificates, potentially leading to data breaches.
What is affected by CVE-2019-18632?
CVE-2019-18632 affects versions of the European Commission eIDAS-Node Integration Package prior to 2.3.1.
Is CVE-2019-18632 related to SAML responses?
Yes, CVE-2019-18632 involves the ability of an attacker to sign manipulated SAML responses with a forged certificate.