CVE-2017-12869
published 2017-09-01CVE-2017-12869: The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication…
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.35%
81.7th percentile
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | simplesamlphp | < simplesamlphp 1.14.15-1 (bookworm) | simplesamlphp 1.14.15-1 (bookworm) |
| simplesamlphp | simplesamlphp | <= 1.14.13 | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.15-1 | 1.14.15-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.15-1 | 1.14.15-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.14 | 1.14.14 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SimpleSAMLphp Authentication context bypass in the multiauth module
ghsa·2022-05-14
CVE-2017-12869 [HIGH] CWE-20 SimpleSAMLphp Authentication context bypass in the multiauth module
SimpleSAMLphp Authentication context bypass in the multiauth module
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
OSV
SimpleSAMLphp Authentication context bypass in the multiauth module
osv·2022-05-14
CVE-2017-12869 [HIGH] SimpleSAMLphp Authentication context bypass in the multiauth module
SimpleSAMLphp Authentication context bypass in the multiauth module
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
OSV
CVE-2017-12869: The multiauth module in SimpleSAMLphp 1
osv·2017-09-01·CVSS 7.5
CVE-2017-12869 [HIGH] CVE-2017-12869: The multiauth module in SimpleSAMLphp 1
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
Debian
CVE-2017-12869: simplesamlphp - The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attacker...
vendor_debian·2017·CVSS 7.5
CVE-2017-12869 [HIGH] CVE-2017-12869: simplesamlphp - The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attacker...
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
Scope: local
bookworm: resolved (fixed in 1.14.15-1)
bullseye: resolved (fixed in 1.14.15-1)
sid: resolved (fixed in 1.14.15-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://simplesamlphp.org/security/201704-02https://www.debian.org/security/2018/dsa-4127https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://simplesamlphp.org/security/201704-02https://www.debian.org/security/2018/dsa-4127
2017-09-01
Published