CVE-2019-3465: High severity Xmlseclibs Project Xmlseclibs vulnerability
Critical signature bypass
Other sources
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/robrichards/xmlseclibsto a version that resolves this vulnerability.Fixed in 2.1.1 - Upgrade
Upgrade
composer/robrichards/xmlseclibsto a version that resolves this vulnerability.Fixed in 3.0.4 - Upgrade
Upgrade
debian/simplesamlphpto a version that resolves this vulnerability.Fixed in 1.19.7-1+deb12u2Fixed in 1.19.7-1+deb12u1Fixed in 2.5.3.1-1 - Upgrade
Upgrade
Rob Richards XmlSecLibsto a version that resolves this vulnerability.Fixed in v3.0.3 - Compensating control
If you cannot immediately upgrade, prevent authenticated attackers from reaching any functionality that would accept/act on the vulnerable XML signatures (restrict access/authorization paths handling incoming XML signature validation).
Event History
Frequently Asked Questions
What is CVE-2019-3465?
CVE-2019-3465 is a vulnerability in Rob Richards XmlSecLibs that allows an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
What software versions are affected by CVE-2019-3465?
XmlSecLibs versions prior to v3.0.3 are affected, as well as SimpleSAMLphp versions 1.16.3-1+deb10u2, 1.16.3-1+deb10u1, 1.19.0-1, and 1.19.7-1.
How severe is CVE-2019-3465?
CVE-2019-3465 has a severity rating of 8.8 (high).
How can I fix CVE-2019-3465?
To fix CVE-2019-3465, update to XmlSecLibs version 3.0.3 and SimpleSAMLphp versions 1.16.3-1+deb10u2, 1.16.3-1+deb10u1, 1.19.0-1, or 1.19.7-1.
Where can I find more information about CVE-2019-3465?
You can find more information about CVE-2019-3465 at the following references: [1] [2] [3].