VYPR
High severity7.5NVD Advisory· Published Mar 5, 2018· Updated Jun 17, 2026

CVE-2018-7644

CVE-2018-7644

Description

The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
simplesamlphp/saml2Packagist
< 1.10.51.10.5
simplesamlphp/saml2Packagist
>= 2.0, < 2.3.72.3.7
simplesamlphp/saml2Packagist
>= 3.0, < 3.1.33.1.3

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.