Insufficient data authenticity validation In simplesamlphp/saml2
Description
SimpleSAMLphp SAML2 spoof SAML responses The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.10.3, 1.8.1, 1.9.1, 2.3.3 | ||
debian 12 | 1.14.10-1 | ||
debian 11 | 1.14.10-1 | ||
debian 14 | 1.14.10-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.