{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-15T00:29:13.772","vulnerabilities":[{"cve":{"id":"CVE-2018-5387","sourceIdentifier":"cret@cert.org","published":"2018-07-24T15:29:01.187","lastModified":"2024-11-21T04:08:43.203","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers."},{"lang":"es","value":"Wizkunde SAMLBase podría utilizar erróneamente los resultados de las API de salto y canonicalización XML DOM de tal forma que un atacante pueda manipular los datos SAML sin invalidar la firma criptográfica, lo que permite que el ataque omita la autenticación de los proveedores de servicio SAML."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cret@cert.org","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wizkunde:samlbase:*:*:*:*:*:*:*:*","versionEndExcluding":"1.4.2","matchCriteriaId":"2ADEA56E-AD76-4B50-B81D-1ED60750A44D"}]}]}],"references":[{"url":"https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations","source":"cret@cert.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/GoGentoOSS/SAMLBase/commit/482cdf8c090e0f1179073034ebcb609ac7c3f5b3","source":"cret@cert.org","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/GoGentoOSS/SAMLBase/issues/3","source":"cret@cert.org","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://www.kb.cert.org/vuls/id/475445","source":"cret@cert.org","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/GoGentoOSS/SAMLBase/commit/482cdf8c090e0f1179073034ebcb609ac7c3f5b3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/GoGentoOSS/SAMLBase/issues/3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Third Party Advisory"]},{"url":"https://www.kb.cert.org/vuls/id/475445","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}