The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.
References
Configurations
No configuration.
History
11 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-11 19:15
Updated : 2025-03-11 19:15
NVD link : CVE-2025-27773
Mitre link : CVE-2025-27773
CVE.ORG link : CVE-2025-27773
JSON object : View
Products Affected
No product.
CWE
CWE-347
Improper Verification of Cryptographic Signature