Bug 1552861 (CVE-2017-18122)

Summary: CVE-2017-18122 php-simplesamlphp-saml2: weak authentication in SAML implementation
Product: [Other] Security Response Reporter: Laura Pardo <lpardo>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: lpardo, shawn
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20171025,reported=20180302,source=bugtraq,cvss3=6.3/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L,cwe=CWE-287,epel-all/php-simplesamlphp-saml2=affected,fedora-all/php-simplesamlphp-saml2=affected
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-04-23 14:00:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 1552864, 1552865    
Bug Blocks:    

Description Laura Pardo 2018-03-07 21:05:56 UTC
The (deprecated) SAML 1.1 implementation would regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signature of at least one of the assertions was valid, allowing an attacker that could obtain a valid signed assertion from an IdP to impersonate users from that IdP.

Comment 1 Laura Pardo 2018-03-07 21:06:05 UTC
External References:

https://simplesamlphp.org/security/201710-01

Comment 2 Laura Pardo 2018-03-07 21:06:25 UTC
Created php-simplesamlphp-saml2 tracking bugs for this issue:

Affects: fedora-all [bug 1552865]
Affects: epel-all [bug 1552864]

Comment 3 Shawn Iwinski 2018-03-07 21:19:34 UTC
CVE-2017-18122 (SSPSA 201710-01) is for the SimpleSAMLphp application not the php-simplesamlphp/saml2 library

Dependent bugs have been closed as not a bug.  Please close this bug as well.

Comment 4 Shawn Iwinski 2018-04-23 04:36:25 UTC
All dependent bugs are closed.  Please close.