Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4270
HistoryMay 22, 2017 - 6:22 a.m.

Security Bypass Via Signature Spoofing

2017-05-2206:22:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.005 Low

EPSS

Percentile

77.0%

simplesamlphp is vulnerable to security bypass via signature spoofing attacks. The attacks are possible because the SimpleSAML_XML_Validator incorrectly checks the return values in the signature validation, thereby allowing an attacker to spoof an invalid signature as valid. This flaw can also lead to other attacks such as denial of service (DoS).