Simplesamlphp
simplesamlphp
31 CVEs • 9 products
Products (9)
Click to collapseToggle
Products (9)
Click to collapse
CVEs (31)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Sep 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the...Show more |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Sep 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the firs...Show more |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Sep 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect...Show more |
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Sep 1, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to im...Show more |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Sep 1, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by l...Show more |
1Simplesamlphp 1Simplesamlphp May 13, 2026 Aug 29, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset. |
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Feb 17, 2017 N/A· v4 6.3 MEDIUM· v3 4.0 MEDIUM· v2 The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging...Show more |
1Simplesamlphp 2Saml2 SimplesamlphpMay 13, 2026 Feb 17, 2017 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML respons...Show more |
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors. |
Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter. |
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL p...Show more |