VYPR
Medium severity5.9NVD Advisory· Published Sep 1, 2017· Updated Jun 17, 2026

CVE-2017-12871

CVE-2017-12871

Description

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
simplesamlphp/simplesamlphpPackagist
>= 1.14.0, < 1.14.121.14.12

Affected products

13
  • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.0:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.0:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.1:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.10:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.11:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.2:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.3:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.4:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.5:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.6:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.7:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.8:*:*:*:*:*:*:*
    • cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.9:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 1.14.0, < 1.14.12

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.