The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
2018-02-02T01:29:00.230
2024-11-21T04:10:49.100
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | simplesamlphp | saml2 | < 1.10.4 | Yes |
Application | simplesamlphp | saml2 | < 2.3.5 | Yes |
Application | simplesamlphp | saml2 | < 3.1.1 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |