High severity7.5NVD Advisory· Published Mar 5, 2018· Updated Jun 17, 2026
CVE-2018-7644
CVE-2018-7644
Description
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
simplesamlphp/saml2Packagist | < 1.10.5 | 1.10.5 |
simplesamlphp/saml2Packagist | >= 2.0, < 2.3.7 | 2.3.7 |
simplesamlphp/saml2Packagist | >= 3.0, < 3.1.3 | 3.1.3 |
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.