Show filters
109 Total Results
Displaying 81-90 of 109
Sort by:
Attacker Value
Unknown
CVE-2018-6519
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
0
Attacker Value
Unknown
CVE-2018-6520
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
0
Attacker Value
Unknown
CVE-2018-6521
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2017-1000433
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
0
Attacker Value
Unknown
CVE-2017-1000452
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
0
Attacker Value
Unknown
CVE-2017-16897
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).
0
Attacker Value
Unknown
CVE-2017-1000246
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
0
Attacker Value
Unknown
CVE-2017-16853
Disclosure Date: November 16, 2017 (last updated November 08, 2023)
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.
0
Attacker Value
Unknown
CVE-2017-12872
Disclosure Date: September 01, 2017 (last updated November 26, 2024)
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
0
Attacker Value
Unknown
CVE-2017-12871
Disclosure Date: September 01, 2017 (last updated November 26, 2024)
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).
0