Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6365
HistoryMay 23, 2018 - 8:16 a.m.

Signature Validation Bypass

2018-05-2308:16:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.003 Low

EPSS

Percentile

68.8%

simplesamlphp/saml2 is vulnerable to signature validation bypass attacks. The vulnerability exists in HTTPRedirect.php due to the reliance of a PHP functionality that interprets a -1 error code as true, allowing signature validation to be bypassed.