cbcvebase.
CVE-2011-4625
published 2019-11-06

CVE-2011-4625: simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiansimplesamlphp< simplesamlphp 1.8.1-1 (bookworm)simplesamlphp 1.8.1-1 (bookworm)
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp>= 0 < 1.8.1-11.8.1-1
simplesamlphpsimplesamlphp>= 0 < 1.8.1-11.8.1-1
simplesamlphpsimplesamlphp>= 0 < 1.8.11.8.1
simplesamlphpsimplesamlphp>= 1.6.0 < 1.6.31.6.3
simplesamlphpsimplesamlphp>= 1.8.0 < 1.8.21.8.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH