MicroHealthLLC / mSend

Fork of Project Send to add more features, security, responsive ui, flattened ui and anonymous sends. There is also single sign on, social media authentication and custom branding. This is a managed file transfer system...large file attachment system to send files up to 2 gigs to another person or group.
https://www.microhealthllc.com
GNU General Public License v2.0
3 stars 2 forks source link

Upgrade robrichards/xmlseclibs to version 2.1.1 or later. #842

Open bluenevus opened 3 years ago

bluenevus commented 3 years ago

CVE-2019-3465 critical severity Vulnerable versions: < 2.1.1 Patched version: 2.1.1 Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.