CVE-2017-12867: Invalid token creation and validation
(updated )
The SimpleSAML_Auth_TimeLimitedToken
class in SimpleSAMLphp allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.
References
Code Behaviors & Features
Detect and mitigate CVE-2017-12867 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →