Lucene search

K
osvGoogleOSV:GHSA-QC43-78VJ-VG7P
HistoryMay 14, 2022 - 1:04 a.m.

SimpleSAMLphp Authentication context bypass in the multiauth module

2022-05-1401:04:19
Google
osv.dev
2

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.8%

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.8%