cbcvebase.
CVE-2017-12871
published 2017-09-01

CVE-2017-12871: The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the…

medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

Affected

16 ranges
VendorProductVersion rangeFixed in
debiansimplesamlphp< simplesamlphp 1.14.15-1 (bookworm)simplesamlphp 1.14.15-1 (bookworm)
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp
simplesamlphpsimplesamlphp>= 0 < 1.14.15-11.14.15-1
simplesamlphpsimplesamlphp>= 0 < 1.14.15-11.14.15-1
simplesamlphpsimplesamlphp>= 1.14.0 < 1.14.121.14.12

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM