CVE-2025-27773
- EPSS 0.08%
- Published 11.03.2025 19:04:52
- Last modified 09.05.2025 20:15:38
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Re...
CVE-2024-52806
- EPSS 0.16%
- Published 02.12.2024 17:15:12
- Last modified 02.12.2024 17:15:12
SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.
CVE-2023-49087
- EPSS 0.21%
- Published 30.11.2023 06:15:47
- Last modified 21.11.2024 08:32:47
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signat...
CVE-2018-7711
- EPSS 0.21%
- Published 05.03.2018 22:29:00
- Last modified 21.11.2024 04:12:34
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation...
CVE-2018-6519
- EPSS 0.4%
- Published 02.02.2018 01:29:00
- Last modified 21.11.2024 04:10:49
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
CVE-2016-9814
- EPSS 0.83%
- Published 17.02.2017 02:59:14
- Last modified 20.04.2025 01:37:25
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial ...