We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue.
Reserved 2025-03-06 | Published 2025-03-11 | Updated 2025-03-11 | Assigner GitHub_MCWE-347: Improper Verification of Cryptographic Signature
github.com/.../saml2/security/advisories/GHSA-46r4-f8gj-xg56
github.com/...ommit/7867d6099dc7f31bed1ea10e5bea159c5623d2a0
github.com/...0469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php
github.com/...0469c5c1e0294f0303e/src/SAML2/HTTPRedirect.php
Support options