QID 730014
Date Published: 2021-04-06
QID 730014: SimpleSAMLphp Information disclosure Vulnerability(201911-02)
SimpleSAMLphp is an award-winning application written in native PHP that deals with authentication.
Affected Versions:
SimpleSAMLphp 1.17.0 - 1.17.7
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of SimpleSAMLphp
An attacker could leverage this issue by accessing the unprotected endpoint and gather intelligence about the host where SimpleSAMLphp is deployed, using it later for their own advantage in case other issues arise.
Solution
Customers are advised upgrade to the SimpleSAMLphp installation to version 1.17.8 latest one.
Vendor References
- 201911-02 -
simplesamlphp.org/security/201911-02
CVEs related to QID 730014
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 201911-02 |
|