{"id":"CVE-2018-1000165","aliases":["GHSA-vg4f-8v9q-5c3x"],"url":"https://o3.security/vulnerability/CVE-2018-1000165","summary":"LightSAML Incorrect Access Control vulnerability","details":"LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/ that can result in impersonation of any user from Identity Provider. This vulnerability appears to have been fixed in 1.3.5 and later.","published":"2018-04-18T19:29:00.770Z","modified":"2026-07-08T12:28:40.369421Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"lightsaml/lightsaml","fixedVersion":"1.3.5"}],"fix":{"url":"https://github.com/lightSAML/lightSAML/commit/47cef07bb09779df15620799f3763d1b8d32307a","label":"lightSAML/lightSAML@47cef07"},"references":[{"type":"ADVISORY","url":"https://github.com/lightSAML/lightSAML/releases/tag/1.3.5"},{"type":"FIX","url":"https://github.com/lightSAML/lightSAML/commit/47cef07bb09779df15620799f3763d1b8d32307a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:28:40.369421Z"}}