Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true boolean value.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SimpleSAMLphp saml2库安全漏洞
Vulnerability Description
SimpleSAMLphp是一套实现了SAML 2.0服务提供者和标识提供者功能的PHP身份验证应用程序。SAML2 library是其中的一个安全声明标记语言库。 SimpleSAMLphp 1.15.4之前版本中的SAML2库的HTTPRedirect.php文件存在安全漏洞,该漏洞源于在签名验证实用程序中,程序没有正确的验证返回值。攻击者可利用该漏洞使设备接受无效签名,并将其视为有效。
CVSS Information
N/A
Vulnerability Type
N/A