8.8

CVE-2019-3465

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.

Data is provided by the National Vulnerability Database (NVD)
Xmlseclibs ProjectXmlseclibs Version >= 1.0.0 <= 1.4.2
Xmlseclibs ProjectXmlseclibs Version >= 2.0.0 <= 2.1.0
Xmlseclibs ProjectXmlseclibs Version >= 3.0.0 <= 3.0.3
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
SimplesamlphpSimplesamlphp Version <= 1.17.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.05% 0.862
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://seclists.org/bugtraq/2019/Nov/8
Third Party Advisory
Mailing List
Issue Tracking