CVE-2011-4625

HIGH7.5EPSS 0.27%

simpleSAMLphp incorrectly handles XML encryption

Published: 4/22/2022Modified: 4/28/2026
Also known as:GHSA-5fj7-f8x3-q2mcDEBIAN-CVE-2011-4625

Description

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (6)