CVE-2018-7644
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
La biblioteca XmlSecLibs, tal y como se utiliza en la biblioteca saml2 en SimpleSAMLphp, en versiones anteriores a la 1.15.3, verifica incorrectamente las firmas en aserciones SAML, lo que permite que un atacante remoto construya una aserción SAML manipulada en nombre de un proveedor de identidad que pasaría como criptográficamente válido. Esto le permitiría suplantar a un usuario de ese proveedor de identidad; este problema también se conoce como confusión de claves.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-02 CVE Reserved
- 2018-03-05 CVE Published
- 2024-08-05 CVE Updated
- 2024-11-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://simplesamlphp.org/security/201802-01 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simplesamlphp Search vendor "Simplesamlphp" | Simplesamlphp Search vendor "Simplesamlphp" for product "Simplesamlphp" | < 1.15.3 Search vendor "Simplesamlphp" for product "Simplesamlphp" and version " < 1.15.3" | - |
Affected
|