{"id":"GHSA-g48f-pgwh-wwxx","summary":"onelogin/php-saml signature wrapping attacks","details":"Vulnerability in onelogin/php-saml versions prior to 2.10.0 allows signature Wrapping attacks which may result in a malicious user gaining unauthorized access to a system.","aliases":["CVE-2016-1000253"],"modified":"2024-12-02T05:44:27.714997Z","published":"2024-05-17T23:06:55Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-17T23:06:55Z"},"references":[{"type":"WEB","url":"https://github.com/onelogin/php-saml/commit/9d31baa97a57b0989020f62d24307c29e325dac3"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/onelogin/php-saml/CVE-2016-1000253.yaml"},{"type":"PACKAGE","url":"https://github.com/SAML-Toolkits/php-saml"}],"affected":[{"package":{"name":"onelogin/php-saml","ecosystem":"Packagist","purl":"pkg:composer/onelogin/php-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.0"}]}],"versions":["2.0.0","2.1.0","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-g48f-pgwh-wwxx/GHSA-g48f-pgwh-wwxx.json"}}],"schema_version":"1.9.0"}