CVE-2017-12867
29.08.2017, 15:29
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.Enginsight
| Vendor | Product | Version |
|---|---|---|
| simplesamlphp | simplesamlphp | 𝑥 ≤ 1.14.14 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| simplesamlphp |
|
Common Weakness Enumeration
References