{"id":"CVE-2017-12871","details":"The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).","aliases":["GHSA-ww3w-592j-5qrw"],"modified":"2026-07-08T05:49:31.967156938Z","published":"2017-09-01T21:29:00.530Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.14.0"},{"last_affected":"1.14.0"}],"source":"CPE_STRING","vendor_product":"simplesamlphp:simplesamlphp"}]},"references":[{"type":"FIX","url":"https://github.com/simplesamlphp/simplesamlphp/commit/77df6a932d46daa35e364925eb73a175010dc904"},{"type":"FIX","url":"https://simplesamlphp.org/security/201703-02"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simplesamlphp/simplesamlphp","events":[{"introduced":"03c6303dfee814450836c4ee3d07d51e628e4d4e"},{"last_affected":"b96dcc500caae73954d4f01189e0209afc6086be"},{"fixed":"77df6a932d46daa35e364925eb73a175010dc904"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.0:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.1:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.2:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.3:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.4:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.5:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.6:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.7:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.8:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.9:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.10:*:*:*:*:*:*:*","cpe:2.3:a:simplesamlphp:simplesamlphp:1.14.11:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.14.0"},{"last_affected":"1.14.0"},{"introduced":"1.14.1"},{"last_affected":"1.14.1"},{"introduced":"1.14.2"},{"last_affected":"1.14.2"},{"introduced":"1.14.3"},{"last_affected":"1.14.3"},{"introduced":"1.14.4"},{"last_affected":"1.14.4"},{"introduced":"1.14.5"},{"last_affected":"1.14.5"},{"introduced":"1.14.6"},{"last_affected":"1.14.6"},{"introduced":"1.14.7"},{"last_affected":"1.14.7"},{"introduced":"1.14.8"},{"last_affected":"1.14.8"},{"introduced":"1.14.9"},{"last_affected":"1.14.9"},{"introduced":"1.14.10"},{"last_affected":"1.14.10"},{"introduced":"1.14.11"},{"last_affected":"1.14.11"}]}}],"versions":["1.14.0","1.14.1","1.14.10","1.14.11","1.14.2","1.14.3","1.14.4","1.14.5","1.14.6","1.14.7","1.14.8","1.14.9","v1.14.2","v1.14.10","v1.14.11","v1.14.9","v1.14.8","v1.14.7","v1.14.6","v1.14.5","v1.14.4","v1.14.3","v1.14.1","v1.14.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-12871.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}