Vulnerability DatabaseGHSA-7wh8-jrq7-p27f

GHSA-7wh8-jrq7-p27f
PHP vulnerability analysis and mitigation

Overview

SimpleSAMLphp versions 1.16.0 through 1.16.2 contained a vulnerability related to credentials exposure in session storage. The issue was discovered on December 13, 2018, and publicly disclosed on December 20, 2018. This moderate severity vulnerability affected the authentication mechanism in SimpleSAMLphp's implementation of the SAML Enhanced Client or Proxy (ECP) profile (SimpleSAMLphp Advisory, GitHub Advisory).

Technical details

The vulnerability occurred when authentication requests were received via the ECP profile, where username and password credentials were saved to the state array for passing between routines. When the ECP profile was disabled in the Identity Provider, the system would default to other bindings like HTTP-POST or HTTP-Redirect. Due to these redirections, the state array containing credentials would be persisted to the user's session and stored in the session backend. The issue stemmed from incorrect logic that assumed SOAP binding usage meant ECP profile was in use, which wasn't always true (SimpleSAMLphp Advisory).

Impact

The vulnerability could result in user credentials being exposed in session storage systems, including local file systems, Memcache, Redis, or relational databases. This exposure made credentials potentially accessible to system administrators, other personnel, or malicious actors who might have access to systems where sessions or their backups were stored (GitHub Advisory).

Exploitability

The vulnerability could be exploited in Identity Providers that had the ECP profile disabled but maintained metadata for entities supporting ECP. In such configurations, incoming ECP requests would be rejected, but the credentials from these requests would still be written to the user's session storage (SimpleSAMLphp Advisory).

Mitigation and workarounds

The vulnerability was patched in SimpleSAMLphp version 1.16.3. The recommended mitigation is to upgrade to this or a later version of SimpleSAMLphp (GitHub Advisory).

Community reactions

The security issue was discovered by Brad Higgins and Jason Baker of Duo Security and reported by Steve Manzuik on December 13, 2018, demonstrating responsible disclosure practices in the security community (SimpleSAMLphp Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management