cbcvebase.
CVE-2023-49087
published 2023-11-30

CVE-2023-49087: xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.19%
9.1th percentile
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.

Affected

6 ranges
VendorProductVersion rangeFixed in
simplesamlphpsaml2
simplesamlphpsaml2>= 5.0.0-alpha.12 < 5.0.0-alpha.135.0.0-alpha.13
simplesamlphpxml-security
simplesamlphpxml-security
simplesamlphpxml-security
simplesamlphpxml-security>= 1.6.11 < 1.6.121.6.12

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.