Vulnerability Description
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simplesamlphp | Simplesamlphp | <= 1.14.12 |
Related Weaknesses (CWE)
References
- https://simplesamlphp.org/security/201704-01PatchVendor Advisory
- https://simplesamlphp.org/security/201704-01PatchVendor Advisory
FAQ
What is CVE-2017-12870?
CVE-2017-12870 is a vulnerability with a CVSS score of 5.9 (MEDIUM). SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Cryp...
How severe is CVE-2017-12870?
CVE-2017-12870 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12870?
Check the references section above for vendor advisories and patch information. Affected products include: Simplesamlphp Simplesamlphp.