CVE-2023-49087

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
30/11/2023
Last modified:
06/12/2023

Description

xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simplesamlphp:saml2:5.0.0:alpha12:*:*:*:*:*:*
cpe:2.3:a:simplesamlphp:xml-security:1.6.11:*:*:*:*:*:*:*