{"id":"CVE-2018-7644","aliases":["GHSA-923w-2xv2-7pr8"],"url":"https://o3.security/vulnerability/CVE-2018-7644","summary":"SimpleSAMLphp Improper Verification of Cryptographic Signature","details":"The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.","published":"2018-03-05T14:29:00.377Z","modified":"2026-07-08T16:41:18.668243Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"simplesamlphp/saml2","fixedVersion":"1.10.5"},{"ecosystem":"Packagist","name":"simplesamlphp/saml2","fixedVersion":"2.3.7"},{"ecosystem":"Packagist","name":"simplesamlphp/saml2","fixedVersion":"3.1.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://simplesamlphp.org/security/201802-01"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:41:18.668243Z"}}