Information Exposure Affecting miniorange/miniorange-saml package, versions <1.4.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Mature
EPSS
0.18% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-MINIORANGEMINIORANGESAML-1577151
  • published31 Aug 2021
  • disclosed31 Aug 2021
  • creditChristoph Schwarzenberg

Introduced: 31 Aug 2021

CVE-2021-36786  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade miniorange/miniorange-saml to version 1.4.2 or higher.

Overview

miniorange/miniorange-saml is a provides SSO/Login to your TYPO3 site with any SAML compliant Identity Provider.

Affected versions of this package are vulnerable to Information Exposure. The extension contains sensitive data (API credentials and private key).

CVSS Scores

version 3.1