cbcvebase.

Debian Simplesamlphp vulnerabilities

27 known vulnerabilities affecting debian/simplesamlphp.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH11MEDIUM9LOW4

Vulnerabilities

Page 2 of 2
CVE-2017-18121P4MEDIUMCVSS 6.1fixed in simplesamlphp 1.15.0-1 (bookworm)2017
CVE-2017-18121 [MEDIUM] CVE-2017-18121: simplesamlphp - The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cros... The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser. Scope: local bookworm: resolved (fixed in 1.15.0-1) bullseye: resolved (fixed in 1.15.0-1) sid: resolved (fixed in 1.15.0-1)
debian
CVE-2017-12870P4MEDIUMCVSS 5.9fixed in simplesamlphp 1.14.15-1 (bookworm)2017
CVE-2017-12870 [MEDIUM] CVE-2017-12870: simplesamlphp - SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers... SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers. Scope: local bookworm: resolved (fixed in 1.14.15-1) bullseye: resolved (fixe
debian
CVE-2018-6520P4MEDIUMCVSS 6.1fixed in simplesamlphp 1.15.2-1 (bookworm)2018
CVE-2018-6520 [MEDIUM] CVE-2018-6520: simplesamlphp - SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect p... SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL. Scope: local bookworm: resolved (fixed in 1.15.2-1) bullseye: resolved (fixed in 1.15.2-1) sid: resolved (fixed in 1.15.2-1)
debian
CVE-2020-5226P4MEDIUMCVSS 4.4fixed in simplesamlphp 1.18.4-1 (bookworm)2020
CVE-2020-5226 [MEDIUM] CVE-2020-5226: simplesamlphp - Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.... Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapper of an external dependency. This new wrapper allows us to us
debian
CVE-2016-9955P4LOWCVSS 6.3fixed in simplesamlphp 1.14.11-1 (bookworm)2016
CVE-2016-9955 [MEDIUM] CVE-2016-9955: simplesamlphp - The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 m... The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean. Scope: local bookworm: resolved (fixed in 1.14.11-1) bullseye: resolved (fixed in 1.14.11-1)
debian
CVE-2012-0040P4MEDIUMCVSS 4.3fixed in simplesamlphp 1.8.2-1 (bookworm)2012
CVE-2012-0040 [MEDIUM] CVE-2012-0040: simplesamlphp - Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in Si... Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter. Scope: local bookworm: resolved (fixed in 1.8.2-1) bullseye: resolved (fixed in 1.8.2-1) sid: resolved (fixed in 1.8.2-1)
debian
CVE-2012-0908P4MEDIUMCVSS 4.3fixed in simplesamlphp 1.8.2-1 (bookworm)2012
CVE-2012-0908 [MEDIUM] CVE-2012-0908: simplesamlphp - Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 an... Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter. Scope: local bookworm: resolved (fixed in 1.8.2-1) bullseye: resolved (fixed in 1.8.2-1) sid: resolved (fixed in 1.8.2-1)
debian
Debian Simplesamlphp vulnerabilities | cvebase