Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SAML Vulnerability #3

Open
rsisco opened this issue Mar 20, 2018 · 2 comments
Open

SAML Vulnerability #3

rsisco opened this issue Mar 20, 2018 · 2 comments
Assignees
Labels

Comments

@rsisco
Copy link
Contributor

rsisco commented Mar 20, 2018

It would appear that this service provider is susceptible to the SAML vulnerability identified by Duo labs. The vulnerability would be in the use of xml-exc-c14n# instead of xml-exc-c14n#WithComments in src/Wizkunde/SAMLBase/Security/Signature.php.

@RonXS
Copy link
Contributor

RonXS commented Apr 5, 2018

Hi @rsisco ,

Thank you for your report, we've fixed this in tag 1.2.7 and our library should no longer be affected.

If you have any further details or do find any way to still exploit this issue, please let us know and we'll get on it with the highest priority.

@RonXS RonXS self-assigned this Apr 5, 2018
@RonXS RonXS added the Security label Apr 5, 2018
@RonXS
Copy link
Contributor

RonXS commented Apr 5, 2018

This is the commit, fixing the affected security issue:

482cdf8

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants