{"id":"GHSA-24m3-w8g9-jwpq","summary":"Information disclosure of source code in SimpleSAMLphp","details":"### Background\n\nThe module controller in `SimpleSAML\\Module` that processes requests for pages\nhosted by modules, has code to identify paths ending with `.php` and process\nthose as PHP code. If no other suitable way of handling the given path exists it\npresents the file to the browser.\n\n### Description\n\nThe check to identify paths ending with `.php` does not account for uppercase\nletters. If someone requests a path ending with e.g. `.PHP` and the server is\nserving the code from a case-insensitive file system, such as on Windows, the\nprocessing of the PHP code does not occur, and the source code is instead\npresented to the browser.\n\n### Affected versions\n\nSimpleSAMLphp versions **1.18.5 and older**.\n\n### Impact\n\nAn attacker may use this issue to gain access to the source code in third-party\nmodules that is meant to be private, or even sensitive. However, the attack\nsurface is considered small, as the attack will only work when SimpleSAMLphp\nserves such content from a file system that is not case-sensitive, such as on\nWindows.\n\n### Resolution\n\nUpgrade the SimpleSAMLphp installation to version **1.18.6**.\n\n### Credit\n\nThis vulnerability was discovered and reported by Sławek Naczyński.","aliases":["CVE-2020-5301"],"modified":"2026-05-07T05:02:09.989666843Z","published":"2020-04-22T20:59:44Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2020-04-21T19:50:30Z","nvd_published_at":"2020-04-21T20:15:00Z","cwe_ids":["CWE-178","CWE-200"]},"references":[{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-24m3-w8g9-jwpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5301"},{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/commit/47968d26a2fd3ed52da70dc09210921d612ce44e"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/CVE-2020-5301.yaml"},{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp"},{"type":"WEB","url":"https://simplesamlphp.org/security/202004-01"}],"affected":[{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.18.6"}]}],"versions":["1.16.0","1.16.0-rc1","1.16.1","1.16.2","1.16.3","v1.12.0","v1.13.0","v1.13.0-rc1","v1.13.0-rc2","v1.13.1","v1.13.2","v1.14.0","v1.14.0-rc1","v1.14.1","v1.14.10","v1.14.11","v1.14.12","v1.14.13","v1.14.14","v1.14.15","v1.14.16","v1.14.17","v1.14.2","v1.14.3","v1.14.4","v1.14.5","v1.14.6","v1.14.7","v1.14.8","v1.14.9","v1.15.0","v1.15.0-rc1","v1.15.0-rc2","v1.15.0-rc3","v1.15.1","v1.15.2","v1.15.3","v1.15.4","v1.17.0","v1.17.0-rc1","v1.17.0-rc2","v1.17.0-rc3","v1.17.1","v1.17.2","v1.17.3","v1.17.4","v1.17.5","v1.17.6","v1.17.7","v1.17.8","v1.18.0","v1.18.0-rc1","v1.18.0-rc2","v1.18.1","v1.18.2","v1.18.3","v1.18.4","v1.18.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-24m3-w8g9-jwpq/GHSA-24m3-w8g9-jwpq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N"}]}