ZeroHour

CVE-2017-12868

CVSS 3.0
9.8 critical
EPSS
2%p81
Published
()
Modified
Description

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

Vendors
simplesamlphp
Products
simplesamlphp
Weakness
CWE-384
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.