Aller au contenu

Fiche vulnérabilité

CVE-2023-49087 : faille élevée simplesamlphp saml2 (CVSS 7.5)

Description

xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
30 nov. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • simplesamlphp saml2
  • simplesamlphp xml-security

Références

Rechercher une autre vulnérabilité dans la base CVE