CVE-2017-12867
29.08.2017, 15:29
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.Enginsight
Vendor | Product | Version |
---|---|---|
simplesamlphp | simplesamlphp | 𝑥 ≤ 1.14.14 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
simplesamlphp |
|
Common Weakness Enumeration
References