cbcvebase.
CVE-2024-52596
published 2024-12-02

CVE-2024-52596: SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible…

high8.8CVSS 4.0
AVNACLATNPRNUINVCHVINVAHSCLSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiansimplesamlphp< simplesamlphp 1.19.7-1+deb12u1 (bookworm)simplesamlphp 1.19.7-1+deb12u1 (bookworm)
simplesamlphpsimplesamlphp>= 0 < 1.19.0-1+deb11u11.19.0-1+deb11u1
simplesamlphpsimplesamlphp>= 0 < 1.19.7-1+deb12u11.19.7-1+deb12u1
simplesamlphpsimplesamlphp>= 0 < 2.0.152.0.15
simplesamlphpsimplesamlphp>= 2.1.0 < 2.1.72.1.7
simplesamlphpsimplesamlphp>= 2.2.0 < 2.2.42.2.4
simplesamlphpsimplesamlphp>= 2.3.0 < 2.3.42.3.4
simplesamlphpxml-common< 1.20.01.20.0
simplesamlphpxml-common>= 0 < 1.20.01.20.0

CVSS provenance

nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa8.8HIGH
osv8.8HIGH