{"id":"GHSA-j5g2-q29x-cw3h","summary":"SimpleSAMLphp vulnerable to XXE in parsing SAML messages","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the vulnerability affects users of the SimpleSAMLphp tarball, not the SimpleSAMLphp Composer package. The underlying information about CVE-2024-52596 is still valid.\n\n## Original Description\n\n# Summary\nWhen loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE.\n\n## Mitigation:\n\nRemove the `LIBXML_DTDLOAD | LIBXML_DTDATTR` options from `$options` is in: https://github.com/simplesamlphp/saml2/blob/717c0adc4877ebd58428637e5626345e59fa0109/src/SAML2/DOMDocumentFactory.php#L41\n\n## Background / details\n\nTo be published on Dec 8th","modified":"2024-12-04T16:25:46.808571Z","published":"2024-12-02T20:00:29Z","withdrawn":"2024-12-04T16:13:50Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-611"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-12-02T20:00:29Z"},"references":[{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-j5g2-q29x-cw3h"},{"type":"WEB","url":"https://github.com/simplesamlphp/xml-common/security/advisories/GHSA-2x65-fpch-2fcm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52596"},{"type":"PACKAGE","url":"https://github.com/simplesamlphp/simplesamlphp"}],"affected":[{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.4"}]}],"versions":["v2.3.0","v2.3.1","v2.3.2","v2.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"}},{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.4"}]}],"versions":["v2.2.0","v2.2.1","v2.2.2","v2.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"}},{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.7"}]}],"versions":["2.1.0","v2.1.1","v2.1.2","v2.1.3","v2.1.4","v2.1.5","v2.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"}},{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.15"}]}],"versions":["1.16.0","1.16.0-rc1","1.16.1","1.16.2","1.16.3","1.19.8","1.19.9","2.0.2","2.0.3","2.0.4","2.0.4-alpha.1","2.0.5","v1.12.0","v1.13.0","v1.13.0-rc1","v1.13.0-rc2","v1.13.1","v1.13.2","v1.14.0","v1.14.0-rc1","v1.14.1","v1.14.10","v1.14.11","v1.14.12","v1.14.13","v1.14.14","v1.14.15","v1.14.16","v1.14.17","v1.14.2","v1.14.3","v1.14.4","v1.14.5","v1.14.6","v1.14.7","v1.14.8","v1.14.9","v1.15.0","v1.15.0-rc1","v1.15.0-rc2","v1.15.0-rc3","v1.15.1","v1.15.2","v1.15.3","v1.15.4","v1.17.0","v1.17.0-rc1","v1.17.0-rc2","v1.17.0-rc3","v1.17.1","v1.17.2","v1.17.3","v1.17.4","v1.17.5","v1.17.6","v1.17.7","v1.17.8","v1.18.0","v1.18.0-rc1","v1.18.0-rc2","v1.18.1","v1.18.2","v1.18.3","v1.18.4","v1.18.5","v1.18.6","v1.18.7","v1.18.8","v1.19.0","v1.19.0-rc1","v1.19.1","v1.19.2","v1.19.3","v1.19.4","v1.19.5","v1.19.6","v1.19.7","v2.0.0","v2.0.0-beta.1","v2.0.0-beta.11","v2.0.0-beta.2","v2.0.0-beta.3","v2.0.0-beta.4","v2.0.0-beta99","v2.0.0-rc1","v2.0.0-rc2","v2.0.0-rc3","v2.0.1","v2.0.10","v2.0.11","v2.0.12","v2.0.13","v2.0.14","v2.0.6","v2.0.7","v2.0.8","v2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-j5g2-q29x-cw3h/GHSA-j5g2-q29x-cw3h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}