Description
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1983-1 | simplesamlphp security update |
Debian DSA |
DSA-4560-1 | simplesamlphp security update |
EUVD |
EUVD-2019-0760 | Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message. |
Github GHSA |
GHSA-pqm6-cgwr-x6pf | Signature validation bypass in XmlSecLibs |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-04T19:12:09.411Z
Reserved: 2018-12-31T00:00:00.000Z
Link: CVE-2019-3465
No data.
Status : Modified
Published: 2019-11-07T20:15:11.090
Modified: 2024-11-21T04:42:06.050
Link: CVE-2019-3465
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA