SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3981-1 simplesamlphp security update
Debian DSA Debian DSA DSA-5822-1 simplesamlphp security update
EUVD EUVD EUVD-2024-3414 SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.
Github GHSA Github GHSA GHSA-2x65-fpch-2fcm SimpleSAMLphp xml-common XXE vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 02 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Simplesamlphp
Simplesamlphp xml-common
CPEs cpe:2.3:a:simplesamlphp:xml-common:*:*:*:*:*:*:*:*
Vendors & Products Simplesamlphp
Simplesamlphp xml-common
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Dec 2024 17:30:00 +0000

Type Values Removed Values Added
References

Mon, 02 Dec 2024 16:45:00 +0000

Type Values Removed Values Added
Description SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.
Title SimpleSAMLphp xml-common XXE vulnerability
Weaknesses CWE-611
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-12-02T18:36:23.399Z

Reserved: 2024-11-14T15:05:46.769Z

Link: CVE-2024-52596

cve-icon Vulnrichment

Updated: 2024-12-02T17:02:40.705Z

cve-icon NVD

Status : Received

Published: 2024-12-02T17:15:12.353

Modified: 2024-12-02T17:15:12.353

Link: CVE-2024-52596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.