QID 740001
Date Published: 2021-04-06
QID 740001: SimpleSAMLphp Credentials Exposure In Session Storage Vulnerability(201812-01)
SimpleSAMLphp is an award-winning application written in native PHP that deals with authentication.
Affected Versions:
SimpleSAMLphp 1.16.0 to 1.16.2.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of SimpleSAMLphp
An Identity Provider with metadata for trusted entities that support the SAML ECP profile, may end up storing the user's credentials received from such entities in its own session storage, whatever that is, in case ECP is actually not enabled in the IdP. Under such circumstances, the credentials may be then accessible to administrators, other personnel or even malicious parties who may have access to the systems where sessions or their backups are stored.
Solution
Customers are advised Upgrade to the latest version of SimpleSAMLphp. For more information please visit 201812-01
Vendor References
- 201812-01 -
simplesamlphp.org/security/201812-01
CVEs related to QID 740001
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 201812-01 |
|