CVE-2017-12873
published 2017-09-01CVE-2017-12873: SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.66%
73.9th percentile
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | simplesamlphp | < simplesamlphp 1.14.11-1 (bookworm) | simplesamlphp 1.14.11-1 (bookworm) |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.11-1 | 1.14.11-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.11-1 | 1.14.11-1 |
| simplesamlphp | simplesamlphp | >= 1.7.0 < 1.14.11 | 1.14.11 |
| simplesamlphp | simplesamlphp | 1.7.0 – 1.14.10 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Incorrect persistent NameID generation in SimpleSAMLphp
ghsa·2020-01-24
CVE-2017-12873 [CRITICAL] CWE-384 Incorrect persistent NameID generation in SimpleSAMLphp
Incorrect persistent NameID generation in SimpleSAMLphp
### Background
When a SimpleSAMLphp Identity Provider is misconfigured, a bug in the software when trying to build a persistent `NameID` to univocally identify the authenticating subject could cause different users to get the same identifier generated, depending on the attributes available for them right after authentication.
Please note that even though this is possible thanks to a bug, **an IdP must be misconfigured** to release persistent `NameID`s even if it is not properly configured to generate them based on the specifics of the deployment.
### Description
Persistent `NameID`s will typically be sent as part of the `Subject` element of a SAML assertion, or as the contents of the `eduPersonTargetedID` attribute. Here is an exam
OSV
Incorrect persistent NameID generation in SimpleSAMLphp
osv·2020-01-24
CVE-2017-12873 [CRITICAL] Incorrect persistent NameID generation in SimpleSAMLphp
Incorrect persistent NameID generation in SimpleSAMLphp
### Background
When a SimpleSAMLphp Identity Provider is misconfigured, a bug in the software when trying to build a persistent `NameID` to univocally identify the authenticating subject could cause different users to get the same identifier generated, depending on the attributes available for them right after authentication.
Please note that even though this is possible thanks to a bug, **an IdP must be misconfigured** to release persistent `NameID`s even if it is not properly configured to generate them based on the specifics of the deployment.
### Description
Persistent `NameID`s will typically be sent as part of the `Subject` element of a SAML assertion, or as the contents of the `eduPersonTargetedID` attribute. Here is an exam
OSV
CVE-2017-12873: SimpleSAMLphp 1
osv·2017-09-01·CVSS 9.8
CVE-2017-12873 [CRITICAL] CVE-2017-12873: SimpleSAMLphp 1
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.
Debian
CVE-2017-12873: simplesamlphp - SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive in...
vendor_debian·2017·CVSS 9.8
CVE-2017-12873 [CRITICAL] CVE-2017-12873: simplesamlphp - SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive in...
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.
Scope: local
bookworm: resolved (fixed in 1.14.11-1)
bullseye: resolved (fixed in 1.14.11-1)
sid: resolved (fixed in 1.14.11-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://simplesamlphp.org/security/201612-04https://www.debian.org/security/2018/dsa-4127https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://simplesamlphp.org/security/201612-04https://www.debian.org/security/2018/dsa-4127
2017-09-01
Published