Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1nZ2o5LTZ4OGotNDl3Oc4AAwss

SimpleSAMLphp simplesamlphp-module-openid

A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0 can address this issue. The name of the patch is d652d41ccaf8c45d5707e741c0c5d82a2365a9a3. It is recommended to upgrade the affected component. VDB-217170 is the identifier assigned to this vulnerability.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Permalink: https://github.com/advisories/GHSA-ggj9-6x8j-49w9
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZ2o5LTZ4OGotNDl3Oc4AAwss
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: 6 months ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-ggj9-6x8j-49w9, CVE-2010-10002
References: Repository: https://github.com/simplesamlphp/simplesamlphp-module-openid
Blast Radius: 7.2

Affected Packages

packagist:simplesamlphp/simplesamlphp-module-openid
Dependent packages: 0
Dependent repositories: 15
Downloads: 14,715 total
Affected Version Ranges: < 1.0
Fixed in: 1.0
All affected versions:
All unaffected versions: