PT-2017-12743 · Simplesamlphp · Simplesamlphp

Jaimeperez

·

Publicado

2017-09-01

·

Atualizado

2020-01-24

·

CVE-2017-12873

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleSAMLphp versions 1.7.0 through 1.14.10
Description The issue arises when a SimpleSAMLphp Identity Provider is misconfigured, leading to incorrect persistent NameID generation. This can cause different users to receive the same identifier, potentially allowing attackers to obtain sensitive information or gain unauthorized access. The problem occurs when the SimpleSAML Auth ProcessingChain class attempts to keep a unique user identifier in the state array, but fails due to missing or empty attributes. As a result, all users connecting to a given service provider may receive the same NameID, which can be used to identify users across sessions. Some service providers have already observed cases where this issue has led to security problems.
Recommendations Upgrade to the latest version. Configure a saml:PersistentNameID authentication processing filter according to your needs, ensuring the attribute used as the source for the NameID is present, unique per user, and does not change over time.

Exploit

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-12873
DLA-1205-1
DSA-4127-1
GHSA-GP2M-7CFP-H6GF

Produtos afetados

Simplesamlphp