The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue. | |
Title | SimpleSAMLphp SAML2 library has incorrect signature verification for HTTP-Redirect binding | |
Weaknesses | CWE-347 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-11T19:27:00.852Z
Reserved: 2025-03-06T18:06:54.460Z
Link: CVE-2025-27773

Updated: 2025-03-11T19:26:53.207Z

Status : Received
Published: 2025-03-11T19:15:43.677
Modified: 2025-03-11T19:15:43.677
Link: CVE-2025-27773

No data.