CVE-2017-18122
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16. A SimpleSAMLphp Service Provider using SAML 1.1 will regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signature of at least one of the assertions is valid. Attributes contained in all the assertions received will be merged and the entityID of the first assertion received will be used, allowing an attacker to impersonate any user of any IdP given an assertion signed by the targeted IdP.
Se ha descubierto un problema de omisión de validación de firmas en SimpleSAMLphp hasta la versión 1.14.16. Un proveedor de servicios SimpleSAMLphp que emplee SAML 1.1 considerará como válida cualquier respuesta SAML que contenga más de una aserción válida, siempre y cuando la firma de, al menos, una de las aserciones sea válida. Los atributos contenidos en todas las aserciones recibidas se fusionarán y se empleará el entityID de la primera aserción recibida. Esto permite que un atacante suplante cualquier usuario de cualquier IdP si tiene una aserción firmada por el IdP objetivo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-02 CVE Reserved
- 2018-02-02 CVE Published
- 2023-08-05 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2018/02/msg00008.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://simplesamlphp.org/security/201710-01 | 2019-05-13 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2018/dsa-4127 | 2019-05-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simplesamlphp Search vendor "Simplesamlphp" | Simplesamlphp Search vendor "Simplesamlphp" for product "Simplesamlphp" | <= 1.14.16 Search vendor "Simplesamlphp" for product "Simplesamlphp" and version " <= 1.14.16" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|