{"id":"GHSA-v858-922f-fj9v","summary":"SimpleSAMLphp Link Injection vulnerability","details":"### Background\nSeveral scripts part of SimpleSAMLphp display a web page with links obtained from the request parameters. This allows us to enhance usability, as the users are presented with links they can follow after completing a certain action, like logging out.\n\n### Description\nThe following scripts were not checking the URLs obtained via the HTTP request before displaying them as the target of links that the user may click on:\n\n- www/logout.php\n- modules/core/www/no_cookie.php\nThe issue allowed attackers to display links targeting a malicious website inside a trusted site running SimpleSAMLphp, due to the lack of security checks involving the link_href and retryURL HTTP parameters, respectively. The issue was resolved by including a verification of the URLs received in the request against a white list of websites specified in the trusted.url.domains configuration option.\n\n### Affected versions\nAll SimpleSAMLphp versions prior to 1.14.4.\n\n### Impact\nA remote attacker could craft a link pointing to a trusted website running SimpleSAMLphp, including a parameter pointing to a malicious website, and try to fool the victim into visiting that website by clicking on a link in the page presented by SimpleSAMLphp.\n","modified":"2024-12-03T06:07:22.402856Z","published":"2024-05-28T18:26:35Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-28T18:26:35Z","nvd_published_at":null,"cwe_ids":["CWE-74"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/commit/b1af4e47c81bca2bee633b3f84f4fde624f359ba"},{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/commit/d26eb8f17dc9916a5ef2fd0a286b0fc96a561e71"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/201606-01.yaml"},{"type":"PACKAGE","url":"https://github.com/simplesamlphp/simplesamlphp"},{"type":"WEB","url":"https://simplesamlphp.org/security/201606-01"}],"affected":[{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.4"}]}],"versions":["v1.12.0","v1.13.0","v1.13.0-rc1","v1.13.0-rc2","v1.13.1","v1.13.2","v1.14.0","v1.14.0-rc1","v1.14.1","v1.14.2","v1.14.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-v858-922f-fj9v/GHSA-v858-922f-fj9v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}