Search CVE reports


Toggle filters

21 – 30 of 31 results


CVE-2017-12872

Medium priority
Vulnerable

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-12871

Medium priority
Vulnerable

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-12870

Medium priority
Vulnerable

SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-12869

Medium priority
Vulnerable

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-12868

Medium priority
Vulnerable

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-12867

Medium priority
Vulnerable

The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-9955

Medium priority
Vulnerable

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-9814

Low priority
Vulnerable

The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or...

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-3124

Low priority
Vulnerable

The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2012-0908

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.

1 affected package

simplesamlphp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
simplesamlphp
Show less packages