CVE-2024-52806
EUVD-2024-349502.12.2024, 17:15
SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| simplesamlphp | saml2 | 𝑥 < 4.6.14 | ADP |
| simplesamlphp | saml2 | 𝑥 ≤ 5.0.0-alpha.1 | ADP |
| simplesamlphp | saml2 | 𝑥 < 5.0.0-alpha.18 | ADP |
Debian Releases
Ubuntu Releases