LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/ that can result in impersonation of any user from Identity Provider. This vulnerability appears to have been fixed in 1.3.5 and later.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5353 | LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/ that can result in impersonation of any user from Identity Provider. This vulnerability appears to have been fixed in 1.3.5 and later. |
Github GHSA |
GHSA-vg4f-8v9q-5c3x | LightSAML Incorrect Access Control vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:49.352Z
Reserved: 2018-04-04T00:00:00
Link: CVE-2018-1000165
No data.
Status : Modified
Published: 2018-04-18T19:29:00.770
Modified: 2024-11-21T03:39:50.013
Link: CVE-2018-1000165
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA