SimpleSAMLphp Session fixation issue and authentication bypass in the authcrypt module
Critical severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated May 5, 2024
Package
Affected versions
>= 1.14.12, < 1.14.14
Patched versions
1.14.14
Description
Published by the National Vulnerability Database
Sep 1, 2017
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Apr 25, 2024
Last updated
May 5, 2024
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.
References