
Cloud Vulnerability DB
A community-led vulnerabilities database
SimpleSAMLphp versions 1.16.0 through 1.16.2 contained a vulnerability related to credentials exposure in session storage. The issue was discovered on December 13, 2018, and publicly disclosed on December 20, 2018. This moderate severity vulnerability affected the authentication mechanism in SimpleSAMLphp's implementation of the SAML Enhanced Client or Proxy (ECP) profile (SimpleSAMLphp Advisory, GitHub Advisory).
The vulnerability occurred when authentication requests were received via the ECP profile, where username and password credentials were saved to the state array for passing between routines. When the ECP profile was disabled in the Identity Provider, the system would default to other bindings like HTTP-POST or HTTP-Redirect. Due to these redirections, the state array containing credentials would be persisted to the user's session and stored in the session backend. The issue stemmed from incorrect logic that assumed SOAP binding usage meant ECP profile was in use, which wasn't always true (SimpleSAMLphp Advisory).
The vulnerability could result in user credentials being exposed in session storage systems, including local file systems, Memcache, Redis, or relational databases. This exposure made credentials potentially accessible to system administrators, other personnel, or malicious actors who might have access to systems where sessions or their backups were stored (GitHub Advisory).
The vulnerability could be exploited in Identity Providers that had the ECP profile disabled but maintained metadata for entities supporting ECP. In such configurations, incoming ECP requests would be rejected, but the credentials from these requests would still be written to the user's session storage (SimpleSAMLphp Advisory).
The vulnerability was patched in SimpleSAMLphp version 1.16.3. The recommended mitigation is to upgrade to this or a later version of SimpleSAMLphp (GitHub Advisory).
The security issue was discovered by Brad Higgins and Jason Baker of Duo Security and reported by Steve Manzuik on December 13, 2018, demonstrating responsible disclosure practices in the security community (SimpleSAMLphp Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."