Lucene search

K
osvGoogleOSV:GHSA-FJ28-869X-VV5G
HistoryMay 14, 2022 - 1:05 a.m.

SimpleSAMLphp InfoCard module Incorrect signature verification

2022-05-1401:05:32
Google
osv.dev
4
simplesamlphp
infocard module
spoofing
xml messages
incorrect signature verification
software

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

61.2%

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

61.2%