
We found results for “”
WS-2017-0250
Good to know:

Date: February 28, 2017
An error during signature verification can be treated as a successful verification.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Insufficient Verification of Data Authenticity
CWE-345Top Fix

Upgrade Version
Upgrade to version onelogin/php-saml - 2.10.4;onelogin/php-saml - dev-deprecation_implicity_nullable;onelogin/php-saml - dev-whitesource/configure;onelogin/php-saml - dev-no_value_nameid;bloomatwork/php-saml - dev-quotespurls;bloomatwork/php-saml - dev-key_rollover_mngmt;bloomatwork/php-saml - 2.10.4;my-oos/my-oos - v2.0.107;performer/php-saml - no_fix;performer/php-saml - 0.1.0;ingeneo/onelogin-php-saml - 2.10.4;ingeneo/onelogin-php-saml - dev-quotespurls;ingeneo/onelogin-php-saml - dev-key_rollover_mngmt;qbnk/php-saml - 2.10.4;radsdev93/php-saml - dev-quotespurls;radsdev93/php-saml - dev-key_rollover_mngmt;radsdev93/php-saml - 2.10.4;workivate/php-saml - dev-quotespurls;workivate/php-saml - dev-dependabot/composer/pdepend/pdepend-2.10.1;workivate/php-saml - dev-dependabot/composer/php-coveralls/php-coveralls-2.6.0;workivate/php-saml - dev-dependabot/github_actions/actions/cache-v2.1.4;workivate/php-saml - dev-dependabot/composer/pdepend/pdepend-2.10.2;workivate/php-saml - dev-dependabot/composer/php-coveralls/php-coveralls-2.5.1;workivate/php-saml - dev-dependabot/composer/pdepend/pdepend-2.9.0;workivate/php-saml - dev-dependabot/github_actions/actions/checkout-2.3.5;workivate/php-saml - 2.10.4;workivate/php-saml - dev-dependabot/github_actions/actions/checkout-2.4.0;workivate/php-saml - dev-dependencies_update;workivate/php-saml - 0.1.0;workivate/php-saml - dev-dependabot/composer/pdepend/pdepend-2.10.3;newfrontiers/php-saml - dev-key_rollover_mngmt;newfrontiers/php-saml - dev-quotespurls;newfrontiers/php-saml - 2.10.4;jakubpas/suitecrm - dev-release
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |