ZeroHour

CVE-2017-12874

CVSS 3.0
7.5 high
EPSS
1%p68
Published
()
Modified
Description

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

Vendors
simplesamlphpdebian
Products
infocard module, debian linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.