QID 996086
Date Published: 2023-11-29
QID 996086: PHP (Composer) Security Update for simplesamlphp/saml2 (GHSA-ww7x-3gxh-qm6r)
Validation of an XML Signature requires verification that the hash value of the related XML-document (after any optional transformations and/or normalizations) matches a specific DigestValue-value, but also that the cryptografic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-ww7x-3gxh-qm6r for updates and patch information.
Vendor References
- GHSA-ww7x-3gxh-qm6r -
github.com/advisories/GHSA-ww7x-3gxh-qm6r
CVEs related to QID 996086
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ww7x-3gxh-qm6r | simplesamlphp/saml2 |
|