CVE-2011-4625
published 2019-11-06CVE-2011-4625: simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | simplesamlphp | < simplesamlphp 1.8.1-1 (bookworm) | simplesamlphp 1.8.1-1 (bookworm) |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.8.1-1 | 1.8.1-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.8.1-1 | 1.8.1-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.8.1 | 1.8.1 |
| simplesamlphp | simplesamlphp | >= 1.6.0 < 1.6.3 | 1.6.3 |
| simplesamlphp | simplesamlphp | >= 1.8.0 < 1.8.2 | 1.8.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH