deanshapira / simplesamlphp-1.15.2

GNU Lesser General Public License v2.1
0 stars 0 forks source link

CVE-2019-3465 (High) detected in robrichards/xmlseclibs-3.0.1 #16

Open mend-for-github-com[bot] opened 6 months ago

mend-for-github-com[bot] commented 6 months ago

CVE-2019-3465 - High Severity Vulnerability

Vulnerable Library - robrichards/xmlseclibs-3.0.1

A PHP library for XML Security

Dependency Hierarchy: - :x: **robrichards/xmlseclibs-3.0.1** (Vulnerable Library)

Found in HEAD commit: 9265509e6f8f33da6589d91be95eae590b521f37

Found in base branch: master

Vulnerability Details

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.

Publish Date: 2019-11-07

URL: CVE-2019-3465

CVSS 3 Score Details (8.8)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: High - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3465

Release Date: 2019-11-07

Fix Resolution: robrichards/xmlseclibs-1.4.3,2.1.1,3.0.4