Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update simplesamlphp/simplesamlphp and simplesamlphp/saml2 libraries #20024

Closed
2 tasks
Tracked by #20017
edmund-dunn opened this issue Dec 4, 2024 · 0 comments · Fixed by #20026
Closed
2 tasks
Tracked by #20017

Update simplesamlphp/simplesamlphp and simplesamlphp/saml2 libraries #20024

edmund-dunn opened this issue Dec 4, 2024 · 0 comments · Fixed by #20026
Assignees
Labels
CMS Team CMS Product team that manages both editor exp and devops DevOps CMS team practice area Drupal engineering CMS team practice area Needs refining Issue status

Comments

@edmund-dunn
Copy link
Contributor

User Story or Problem Statement

On 2 Dec 2024 there were 3 vulnerabilities announced for simplesamlphp. They are listed below.

Description or Additional Context

Found 3 security vulnerability advisories affecting 2 packages:
+-------------------+----------------------------------------------------------------------------------+
| Package           | simplesamlphp/saml2                                                              |
| Severity          | medium                                                                           |
| CVE               | CVE-2024-52806                                                                   |
| Title             | SimpleSAMLphp SAML2 has an XXE in parsing SAML messages                          |
| URL               | https://github.com/advisories/GHSA-pxm4-r5ph-q2m2                                |
| Affected versions | >=5.0.0-alpha.1,<5.0.0-alpha.18|<4.6.14                                          |
| Reported at       | 2024-12-02T17:25:43+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | simplesamlphp/saml2                                                              |
| Severity          | high                                                                             |
| CVE               | CVE-2024-52596                                                                   |
| Title             | SimpleSAMLphp xml-common XXE vulnerability                                       |
| URL               | https://github.com/advisories/GHSA-2x65-fpch-2fcm                                |
| Affected versions | <4.6.14                                                                          |
| Reported at       | 2024-12-02T17:14:30+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | simplesamlphp/simplesamlphp                                                      |
| Severity          | high                                                                             |
| CVE               | NO CVE                                                                           |
| Title             | SimpleSAMLphp vulnerable to XXE in parsing SAML messages                         |
| URL               | https://github.com/advisories/GHSA-j5g2-q29x-cw3h                                |
| Affected versions | <2.0.15|>=2.1.0,<2.1.7|>=2.2.0,<2.2.4|>=2.3.0,<2.3.4                             |
| Reported at       | 2024-12-02T20:00:29+00:00                                                        |
| Advisory ID       | PKSA-5hp7-ndvs-4c4w                                                              |
+-------------------+----------------------------------------------------------------------------------+

Steps for Implementation

Acceptance Criteria

  • Update simplesamlphp/saml2 to <= v4.6.14
  • Update 'simplesamlphp/simplesamlphp` to <= v2.3.4
@edmund-dunn edmund-dunn added CMS Team CMS Product team that manages both editor exp and devops DevOps CMS team practice area Drupal engineering CMS team practice area Needs refining Issue status labels Dec 4, 2024
@edmund-dunn edmund-dunn self-assigned this Dec 4, 2024
@edmund-dunn edmund-dunn linked a pull request Dec 4, 2024 that will close this issue
20 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CMS Team CMS Product team that manages both editor exp and devops DevOps CMS team practice area Drupal engineering CMS team practice area Needs refining Issue status
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant