Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7092
HistoryJul 18, 2018 - 6:12 a.m.

Authentication Bypass

2018-07-1806:12:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

64.4%

SimpleSAMLphp is vulnerable to authentication bypasses. A malicious user can pass an unsigned SAML response with multiple assertions to the application. As long as one of the assertions are valid the application will consider the SAML response valid and grant access to the malicious user.

CPENameOperatorVersion
simplesamlphp/simplesamlphple1.14.16