{"id":"GHSA-ww3w-592j-5qrw","summary":"SimpleSAMLphp Incorrect IV generation for encryption","details":"The aesEncrypt method in `lib/SimpleSAML/Utils/Crypto.php` in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).","aliases":["CVE-2017-12871"],"modified":"2024-04-25T21:26:44.794344Z","published":"2022-05-17T01:17:12Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-25T21:00:11Z","nvd_published_at":"2017-09-01T21:29:00Z","cwe_ids":["CWE-326"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-12871"},{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/commit/77df6a932d46daa35e364925eb73a175010dc904"},{"type":"WEB","url":"https://github.com/simplesamlphp/simplesamlphp/commit/ccf75981187aa88f7165abdb1b1965c0934acda0"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/CVE-2017-12871.yaml"},{"type":"PACKAGE","url":"https://github.com/simplesamlphp/simplesamlphp"},{"type":"WEB","url":"https://simplesamlphp.org/security/201703-02"}],"affected":[{"package":{"name":"simplesamlphp/simplesamlphp","ecosystem":"Packagist","purl":"pkg:composer/simplesamlphp/simplesamlphp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.14.0"},{"fixed":"1.14.12"}]}],"versions":["v1.14.0","v1.14.1","v1.14.10","v1.14.11","v1.14.2","v1.14.3","v1.14.4","v1.14.5","v1.14.6","v1.14.7","v1.14.8","v1.14.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-ww3w-592j-5qrw/GHSA-ww3w-592j-5qrw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}