| Vulnerability Name: | CVE-2019-3465 (CCN-171039) | ||||||||||||||||
| Assigned: | 2018-12-31 | ||||||||||||||||
| Published: | 2019-11-06 | ||||||||||||||||
| Updated: | 2020-08-24 | ||||||||||||||||
| Summary: | Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message. | ||||||||||||||||
| CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||||||
| Vulnerability Type: | CWE-347 | ||||||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-3465 Source: XF Type: UNKNOWN debian-cve20193465-sec-bypass(171039) Source: MISC Type: Patch https://github.com/robrichards/xmlseclibs/commit/0a53d3c3aa87564910cae4ed01416441d3ae0db5 Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20191106 [SECURITY] [DLA 1983-1] simplesamlphp security update Source: FEDORA Type: UNKNOWN FEDORA-2019-73d0fe1d15 Source: FEDORA Type: UNKNOWN FEDORA-2019-9a960c8a98 Source: FEDORA Type: UNKNOWN FEDORA-2020-46d0f456a9 Source: FEDORA Type: UNKNOWN FEDORA-2020-1b95d7a131 Source: FEDORA Type: UNKNOWN FEDORA-2019-be01267416 Source: FEDORA Type: UNKNOWN FEDORA-2019-ec8719a21c Source: FEDORA Type: UNKNOWN FEDORA-2019-81f61cdceb Source: FEDORA Type: UNKNOWN FEDORA-2020-af82229ae5 Source: FEDORA Type: UNKNOWN FEDORA-2019-dc90bf093b Source: CCN Type: Debian Web site simplesamlphp package Source: BUGTRAQ Type: Issue Tracking, Mailing List, Third Party Advisory 20191106 [SECURITY] [DSA 4560-1] simplesamlphp security update Source: CCN Type: BugTraq Mailing List, Wed, 6 Nov 2019 14:42:57 +0100 (CET) [SECURITY] [DSA 4560-1] simplesamlphp security update Source: MISC Type: Third Party Advisory https://simplesamlphp.org/security/201911-01 Source: DEBIAN Type: Third Party Advisory DSA-4560 Source: CONFIRM Type: UNKNOWN https://www.tenable.com/security/tns-2019-09 Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-3465 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||