CVE-2023-49087: Validation of SignedInfo
Validation of an XML Signature requires verification that the hash value of the related XML-document (after any optional transformations and/or normalizations) matches a specific DigestValue-value, but also that the cryptografic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key.
Within the simpleSAMLphp/xml-security library (https://github.com/simplesamlphp/xml-security), the hash is being validated using SignedElementTrait::validateReference, and the signature is being verified in SignedElementTrait::verifyInternal
https://github.com/simplesamlphp/xml-security/blob/master/src/XML/SignedElementTrait.php:
!afbeelding
What stands out is that the signature is being calculated over the canonical version of the SignedInfo-tree. The validateReference method, however, uses the original non-canonicalized version of SignedInfo.
Impact If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be potentially be possible to forge the signature. No possibilities to exploit this were found during the investigation.
Other sources
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-49087?
CVE-2023-49087 is a vulnerability that involves the validation of an XML Signature and the verification of the hash value of the related XML document.
How does CVE-2023-49087 impact the affected software?
CVE-2023-49087 impacts the affected software by allowing an attacker to bypass the verification of the hash value and potentially perform unauthorized actions.
What is the severity of CVE-2023-49087?
CVE-2023-49087 has a severity value of 6.8, which is classified as medium.
How can I fix CVE-2023-49087?
To fix CVE-2023-49087, you should update the affected software to the recommended versions: simplesamlphp/saml2 v5.0.0-alpha.13 and simplesamlphp/xml-security v1.6.12.
Where can I find more information about CVE-2023-49087?
You can find more information about CVE-2023-49087 in the following references: [GitHub Advisory](https://github.com/simplesamlphp/xml-security/security/advisories/GHSA-ww7x-3gxh-qm6r), [Commit Details](https://github.com/simplesamlphp/xml-security/commit/f509e3083dd7870cce5880c804b5122317287581), and [Source Code](https://github.com/simplesamlphp/xml-security/blob/master/src/XML/SignedElementTrait.php).