Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22378
HistoryJan 28, 2020 - 5:04 a.m.

CRLF Injection

2020-01-2805:04:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.001 Low

EPSS

Percentile

22.7%

simplesamlphp/simplesamlphp is vulnerable to CRLF injection. The vulnerability exists as the file logging handler is configured to be used with simplesamlphp, allowing the unsanitized values of reportID to be used to inject newline characters into logs.

CPENameOperatorVersion
simplesamlphp/simplesamlphple1.18.3

0.001 Low

EPSS

Percentile

22.7%