CVE-2017-12868: Session fixation issue and authentication bypass
(updated )
The secureCompare
method in lib/SimpleSAML/Utils/Crypto
when used with PHP, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.
References
Code Behaviors & Features
Detect and mitigate CVE-2017-12868 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →