Bug 1552861 (CVE-2017-18122) - CVE-2017-18122 php-simplesamlphp-saml2: weak authentication in SAML implementation
Summary: CVE-2017-18122 php-simplesamlphp-saml2: weak authentication in SAML implement...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2017-18122
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1552864 1552865
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-03-07 21:05 UTC by Laura Pardo
Modified: 2021-02-17 00:40 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-04-23 14:00:45 UTC
Embargoed:


Attachments (Terms of Use)

Description Laura Pardo 2018-03-07 21:05:56 UTC
The (deprecated) SAML 1.1 implementation would regard as valid any unsigned SAML response containing more than one signed assertion, provided that the signature of at least one of the assertions was valid, allowing an attacker that could obtain a valid signed assertion from an IdP to impersonate users from that IdP.

Comment 1 Laura Pardo 2018-03-07 21:06:05 UTC
External References:

https://simplesamlphp.org/security/201710-01

Comment 2 Laura Pardo 2018-03-07 21:06:25 UTC
Created php-simplesamlphp-saml2 tracking bugs for this issue:

Affects: fedora-all [bug 1552865]
Affects: epel-all [bug 1552864]

Comment 3 Shawn Iwinski 2018-03-07 21:19:34 UTC
CVE-2017-18122 (SSPSA 201710-01) is for the SimpleSAMLphp application not the php-simplesamlphp/saml2 library

Dependent bugs have been closed as not a bug.  Please close this bug as well.

Comment 4 Shawn Iwinski 2018-04-23 04:36:25 UTC
All dependent bugs are closed.  Please close.


Note You need to log in before you can comment on or make changes to this bug.