
We found results for “”
WS-2017-0249
Good to know:

Date: October 14, 2016
Vulnerability to Response Wrapping attacks resulting in a malicious user gaining unauthorized access to a system.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Access Control
CWE-284Top Fix

Upgrade Version
Upgrade to version workivate/php-saml - dev-dependabot/github_actions/actions/checkout-2.4.0;workivate/php-saml - dev-dependabot/github_actions/actions/cache-v2.1.4;workivate/php-saml - 2.10.0;workivate/php-saml - dev-dependabot/composer/php-coveralls/php-coveralls-2.6.0;workivate/php-saml - dev-dependabot/composer/pdepend/pdepend-2.9.0;workivate/php-saml - dev-dependabot/github_actions/actions/checkout-2.3.5;workivate/php-saml - dev-dependabot/composer/php-coveralls/php-coveralls-2.5.1;onelogin/php-saml - 2.10.0;qbnk/php-saml - 2.10.0;ingeneo/onelogin-php-saml - 2.10.0;radsdev93/php-saml - 2.10.0;performer/php-saml - 0.1.0;performer/php-saml - no_fix;bloomatwork/php-saml - 2.10.0;newfrontiers/php-saml - 2.10.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | NONE |