CVE Vulnerabilities

CVE-2017-12873

Session Fixation

Published: Sep 01, 2017 | Modified: Oct 03, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Simplesamlphp Simplesamlphp 1.7.0 (including) 1.14.10 (including)
Simplesamlphp Ubuntu esm-apps/xenial *
Simplesamlphp Ubuntu trusty *
Simplesamlphp Ubuntu upstream *
Simplesamlphp Ubuntu xenial *
Simplesamlphp Ubuntu zesty *

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References