SAML Assertion Signature Verification Issue in SimpleSAMLphp
CVE-2018-7644
7.5HIGH
What is CVE-2018-7644?
The XmlSecLibs library used within the SAML2 library of SimpleSAMLphp prior to version 1.15.3 has a flaw in its signature verification process for SAML assertions. Due to this vulnerability, a remote attacker can craft a malicious SAML assertion that appears valid when verified, enabling them to impersonate legitimate users from an Identity Provider. This issue represents a key confusion problem that compromises the integrity of user authentication processes.
