Lucene search

K
osvGoogleOSV:GHSA-597C-MH7M-48V7
HistoryMay 13, 2022 - 1:42 a.m.

SimpleSAMLphp Invalid token creation and validation

2022-05-1301:42:46
Google
osv.dev
3
simplesamlphp
auth_timelimitedtoken
security vulnerability
token manipulation

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

50.9%

The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

50.9%