Sensitive information sent insecurely In simplesamlphp/simplesamlphp
Description
SimpleSAMLphp Unauthenticated encryption in CBC mode SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.14.13 | ||
debian 12 | 1.14.15-1 | ||
debian 11 | 1.14.15-1 | ||
debian 14 | 1.14.15-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.