Debian Simplesamlphp vulnerabilities
27 known vulnerabilities affecting debian/simplesamlphp.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH11MEDIUM9LOW4
Vulnerabilities
Page 2 of 2
CVE-2017-18121P4MEDIUMCVSS 6.1fixed in simplesamlphp 1.15.0-1 (bookworm)2017
CVE-2017-18121 [MEDIUM] CVE-2017-18121: simplesamlphp - The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cros...
The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.
Scope: local
bookworm: resolved (fixed in 1.15.0-1)
bullseye: resolved (fixed in 1.15.0-1)
sid: resolved (fixed in 1.15.0-1)
debian
CVE-2017-12870P4MEDIUMCVSS 5.9fixed in simplesamlphp 1.14.15-1 (bookworm)2017
CVE-2017-12870 [MEDIUM] CVE-2017-12870: simplesamlphp - SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers...
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.
Scope: local
bookworm: resolved (fixed in 1.14.15-1)
bullseye: resolved (fixe
debian
CVE-2018-6520P4MEDIUMCVSS 6.1fixed in simplesamlphp 1.15.2-1 (bookworm)2018
CVE-2018-6520 [MEDIUM] CVE-2018-6520: simplesamlphp - SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect p...
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
Scope: local
bookworm: resolved (fixed in 1.15.2-1)
bullseye: resolved (fixed in 1.15.2-1)
sid: resolved (fixed in 1.15.2-1)
debian
CVE-2020-5226P4MEDIUMCVSS 4.4fixed in simplesamlphp 1.18.4-1 (bookworm)2020
CVE-2020-5226 [MEDIUM] CVE-2020-5226: simplesamlphp - Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport....
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapper of an external dependency. This new wrapper allows us to us
debian
CVE-2016-9955P4LOWCVSS 6.3fixed in simplesamlphp 1.14.11-1 (bookworm)2016
CVE-2016-9955 [MEDIUM] CVE-2016-9955: simplesamlphp - The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 m...
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Scope: local
bookworm: resolved (fixed in 1.14.11-1)
bullseye: resolved (fixed in 1.14.11-1)
debian
CVE-2012-0040P4MEDIUMCVSS 4.3fixed in simplesamlphp 1.8.2-1 (bookworm)2012
CVE-2012-0040 [MEDIUM] CVE-2012-0040: simplesamlphp - Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in Si...
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
debian
CVE-2012-0908P4MEDIUMCVSS 4.3fixed in simplesamlphp 1.8.2-1 (bookworm)2012
CVE-2012-0908 [MEDIUM] CVE-2012-0908: simplesamlphp - Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 an...
Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
debian
← Previous2 / 2