Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/ that can result in impersonation of any user from Identity Provider. This vulnerability appears to have been fixed in 1.3.5 and later.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LightSAML 访问控制错误漏洞
Vulnerability Description
LightSAML是一个用于实现OASIS SAML 2.0协议的PHP库。 LightSAML 1.3.5之前版本中的src/LightSaml/Model/XmlDSig/的readers的签名校验存在访问控制错误漏洞。攻击者可利用该漏洞冒充任意的Identity Provider用户。
CVSS Information
N/A
Vulnerability Type
N/A