CyberRota Analysis
AI-GeneratedSimpleSAMLphp versions prior to 1.18.6 are vulnerable to an information disclosure flaw that allows an attacker to exploit the SAML SP ACS path, potentially bypassing IdP-specific flows and linking responses from one trusted IdP to SP states created for another. This can lead to unauthorized access and data exposure, particularly in environments where IdP selection is critical. Organizations using SimpleSAMLphp, especially those with strict IdP configurations, should prioritize upgrading to versions 2.4.7 or 2.5.2 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking SubjectConfirmationData/InResponseTo, allowing a response issued by one trusted IdP to be bound to SP state created for another IdP and bypass flows that route users to a specific IdP, including deployments that set enable_unsolicited to false. This issue is fixed in versions 2.4.7 and 2.5.2.
Related CVEs
Other vulnerabilities affecting the same vendor(s)