CVE-2017-12867

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/08/2017
Last modified:
20/04/2025

Description

The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simplesamlphp:simplesamlphp:*:*:*:*:*:*:*:* 1.14.14 (including)