<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:44:29 +0000</lastBuildDate>
    <item>
      <title>cnvd-2017-31287</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-31287</link>
      <description>cnvd-2017-31287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-31287</guid>
    </item>
    <item>
      <title>EUVD-2026-77346</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-77346</link>
      <description>EUVD-2026-77346</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-77346</guid>
    </item>
    <item>
      <title>fkie_cve-2017-12873</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12873</link>
      <description>&lt;p&gt;SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-12873</guid>
    </item>
    <item>
      <title>GHSA-gp2m-7cfp-h6gf — Incorrect persistent NameID generation in SimpleSAMLphp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gp2m-7cfp-h6gf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: simplesamlphp/simplesamlphp&lt;/p&gt;
&lt;p&gt;### Background
When a SimpleSAMLphp Identity Provider is misconfigured, a bug in the software when trying to build a persistent `NameID` to univocally identify the authenticating subject could cause different users to get the same identifier generated, depending on the attributes available for them right after authentication.&lt;/p&gt;
&lt;p&gt;Please note that even though this is possible thanks to a bug, **an IdP must be misconfigured** to release persistent `NameID`s even if it is not properly configured to generate them based on the specifics of the deployment.&lt;/p&gt;
&lt;p&gt;### Description
Persistent `NameID`s will typically be sent as part of the `Subject` element of a SAML assertion, or as the contents of the `eduPersonTargetedID` attribute. Here is an example of such a `NameID`:&lt;/p&gt;
&lt;p&gt;&amp;lt;NameID Format=“urn:oasis:names:tc:SAML:2.0:nameid-format:persistent“&amp;gt;
        zbonsm0Yn9Gnw14uQEEPr6AO7d+IvxwCQN3t+o24jYs=
    &amp;lt;/NameID&amp;gt;&lt;/p&gt;
&lt;p&gt;Some service providers will use this information to identify a user across sessions because a persistent `NameID` will never change for a given user. This could lead to different users accessing the same account in those service providers.&lt;/p&gt;
&lt;p&gt;In order to be affected by this issue, the following circumstances must concur:&lt;/p&gt;
&lt;p&gt;- SimpleSAMLphp acts as an identity provider.
- The service provider asking for authentication requests a persistent `NameID`.
- No `saml:PersistentNameID` authentication processing filter is configured (neither for the whole IdP, nor for a given SP).
- No `simplesa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: simplesamlphp/simplesamlphp&lt;/p&gt;
&lt;p&gt;### Background
When a SimpleSAMLphp Identity Provider is misconfigured, a bug in the software when trying to build a persistent `NameID` to univocally identify the authenticating subject could cause different users to get the same identifier generated, depending on the attributes available for them right after authentication.&lt;/p&gt;
&lt;p&gt;Please note that even though this is possible thanks to a bug, **an IdP must be misconfigured** to release persistent `NameID`s even if it is not properly configured to generate them based on the specifics of the deployment.&lt;/p&gt;
&lt;p&gt;### Description
Persistent `NameID`s will typically be sent as part of the `Subject` element of a SAML assertion, or as the contents of the `eduPersonTargetedID` attribute. Here is an example of such a `NameID`:&lt;/p&gt;
&lt;p&gt;&amp;lt;NameID Format=“urn:oasis:names:tc:SAML:2.0:nameid-format:persistent“&amp;gt;
        zbonsm0Yn9Gnw14uQEEPr6AO7d+IvxwCQN3t+o24jYs=
    &amp;lt;/NameID&amp;gt;&lt;/p&gt;
&lt;p&gt;Some service providers will use this information to identify a user across sessions because a persistent `NameID` will never change for a given user. This could lead to different users accessing the same account in those service providers.&lt;/p&gt;
&lt;p&gt;In order to be affected by this issue, the following circumstances must concur:&lt;/p&gt;
&lt;p&gt;- SimpleSAMLphp acts as an identity provider.
- The service provider asking for authentication requests a persistent `NameID`.
- No `saml:PersistentNameID` authentication processing filter is configured (neither for the whole IdP, nor for a given SP).
- No `simplesa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gp2m-7cfp-h6gf</guid>
    </item>
    <item>
      <title>gsd-2017-12873</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-12873</link>
      <description>gsd-2017-12873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-12873</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-12873</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-12873</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: simplesamlphp&lt;/p&gt;
&lt;p&gt;SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: simplesamlphp&lt;/p&gt;
&lt;p&gt;SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-12873</guid>
    </item>
  </channel>
</rss>
