Vulnerabilities
Vulnerable Software
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.
CVSS Score
9.8
EPSS Score
0.007
Published
2017-09-01
The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.
CVSS Score
7.5
EPSS Score
0.004
Published
2017-09-01
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.
CVSS Score
5.9
EPSS Score
0.002
Published
2017-08-29


Contact Us

Shodan ® - All rights reserved