Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-49087
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Validation of SignedInfo
Source: NVD (National Vulnerability Database)
Vulnerability Description
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
对数据真实性的验证不充分
Source: NVD (National Vulnerability Database)
Vulnerability Title
xml-security 数据伪造问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
xml-security是SimpleSAMLphp开源的一个库。 xml-security 1.6.11版本、saml2 5.0.0-alpha.13版本存在数据伪造问题漏洞,该漏洞源于XML 签名验证需要验证相关 XML 文档的哈希值是否与特定的 DigestValue 值匹配,而且还需要验证 SignedInfo 树上的加密签名并匹配受信任的公钥, 攻击者利用该漏洞可以以某种方式操纵规范化版本的 DigestValue,并可能伪造签名。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
simplesamlphpxml-security = 1.6.11 -
II. Public POCs for CVE-2023-49087
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-49087
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-49087

No comments yet


Leave a comment