CVE-2017-12873

CRITICAL

SimpleSAMLphp <1.14.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

References (4)

Core 4
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html
Patch, Vendor Advisory x_refsource_confirm
https://simplesamlphp.org/security/201612-04
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4127

Scores

CVSS v3 9.8
EPSS 0.0166
EPSS Percentile 73.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (5)
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
simplesamlphp/simplesamlphp 1.7.0 - 1.14.10
simplesamlphp/simplesamlphp 1.7.0 - 1.14.11Packagist
Published Sep 01, 2017
Tracked Since Feb 18, 2026