Publish Advisories

GHSA-9r9m-ffp6-9x4v
GHSA-pxm4-r5ph-q2m2
This commit is contained in:
advisory-database[bot]
2024-12-02 17:26:53 +00:00
parent 9414344a1f
commit 5ff0cc559a
2 changed files with 365 additions and 0 deletions
File diff suppressed because one or more lines are too long
@@ -0,0 +1,144 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxm4-r5ph-q2m2",
"modified": "2024-12-02T17:25:43Z",
"published": "2024-12-02T17:25:43Z",
"aliases": [
"CVE-2024-52806"
],
"summary": "SimpleSAMLphp SAML2 has an XXE in parsing SAML messages",
"details": "# Summary\nWhen loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE.\n\n## Mitigation:\n\nRemove the `LIBXML_DTDLOAD | LIBXML_DTDATTR` options from `$options` is in: https://github.com/simplesamlphp/saml2/blob/717c0adc4877ebd58428637e5626345e59fa0109/src/SAML2/DOMDocumentFactory.php#L41\n\n## Background / details\n\nTo be published on Dec 8th",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "simplesamlphp/saml2"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6.14"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "simplesamlphp/xml-common"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.20.0"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "< 1.20"
}
},
{
"package": {
"ecosystem": "Packagist",
"name": "simplesamlphp/xml-security"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.10.0"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "simplesamlphp/saml2-legacy"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6.14"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "simplesamlphp/saml2"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.0.0-alpha.1"
},
{
"fixed": "5.0.0-alpha.18"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/simplesamlphp/saml2/security/advisories/GHSA-pxm4-r5ph-q2m2"
},
{
"type": "WEB",
"url": "https://github.com/simplesamlphp/saml2/commit/5fd4ce4596656fb0c1278f15b8305825412e89f7"
},
{
"type": "PACKAGE",
"url": "https://github.com/simplesamlphp/saml2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-12-02T17:25:43Z",
"nvd_published_at": null
}
}