cbcvebase.
CVE-2017-12869
published 2017-09-01

CVE-2017-12869: The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication…

high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiansimplesamlphp< simplesamlphp 1.14.15-1 (bookworm)simplesamlphp 1.14.15-1 (bookworm)
simplesamlphpsimplesamlphp<= 1.14.13
simplesamlphpsimplesamlphp>= 0 < 1.14.15-11.14.15-1
simplesamlphpsimplesamlphp>= 0 < 1.14.15-11.14.15-1
simplesamlphpsimplesamlphp>= 0 < 1.14.141.14.14

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH