CVE-2023-49087
If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
xml-security is a library that implements XML signatures and encryption. Validation of an XML signature requires verification that the hash value of the related XML-document matches a specific DigestValue-value, but also that the cryptographic signature on the SignedInfo-tree (the one that contains the DigestValue) verifies and matches a trusted public key. If an attacker somehow (i.e. by exploiting a bug in PHP's canonicalization function) manages to manipulate the canonicalized version's DigestValue, it would be possible to forge the signature. This issue has been patched in version 1.6.12 and 5.0.0-alpha.13.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Affected
- simplesamlphp/saml2 · simplesamlphp/xml-security
- Source
- security-advisories@github.com
References
- https://github.com/simplesamlphp/xml-security/commit/f509e3083dd7870cce5880c804b5122317287581Patch
- https://github.com/simplesamlphp/xml-security/security/advisories/GHSA-ww7x-3gxh-qm6rExploit, Vendor Advisory
- https://github.com/simplesamlphp/xml-security/commit/f509e3083dd7870cce5880c804b5122317287581Patch
- https://github.com/simplesamlphp/xml-security/security/advisories/GHSA-ww7x-3gxh-qm6rExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.