USN-8770-1

Source
https://ubuntu.com/security/notices/USN-8770-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8770-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-8770-1
Upstream
Related
Published
2026-09-15T16:16:00Z
Modified
2026-09-16T02:57:30Z
Summary
simplesamlphp vulnerabilities
Details

It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)

It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents. A remote attacker could possibly use this issue to obtain sensitive information. This issue did not affect Ubuntu 24.04 LTS. (CVE-2024-52596)

It was discovered that SimpleSAMLphp incorrectly verified signatures in SAML messages using the HTTP-Redirect binding. A remote attacker could possibly use this issue to bypass authentication and impersonate users. (CVE-2025-27773)

References

Affected packages

Ubuntu:Pro:16.04:LTS / simplesamlphp

Package

Name
simplesamlphp
Purl
pkg:deb/ubuntu/simplesamlphp?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.14.0-1ubuntu2+esm1

Affected versions

1.*
1.13.2-1
1.14.0-1
1.14.0-1ubuntu2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "simplesamlphp",
            "binary_version": "1.14.0-1ubuntu2+esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2019-3465",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-52596",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-27773",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:16.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8770-1.json"

Ubuntu:Pro:18.04:LTS / simplesamlphp

Package

Name
simplesamlphp
Purl
pkg:deb/ubuntu/simplesamlphp?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.15.3-1ubuntu0.1~esm1

Affected versions

1.*
1.14.15-1
1.15.0-1
1.15.1-1
1.15.2-1
1.15.3-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "simplesamlphp",
            "binary_version": "1.15.3-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2019-3465",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2024-52596",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-27773",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:18.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8770-1.json"

Ubuntu:Pro:20.04:LTS / simplesamlphp

Package

Name
simplesamlphp
Purl
pkg:deb/ubuntu/simplesamlphp?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.18.4-1ubuntu0.1~esm1

Affected versions

1.*
1.17.5-1
1.17.6-1
1.17.6-2
1.18.1-1
1.18.4-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "simplesamlphp",
            "binary_version": "1.18.4-1ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2024-52596",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-27773",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:20.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8770-1.json"

Ubuntu:Pro:22.04:LTS / simplesamlphp

Package

Name
simplesamlphp
Purl
pkg:deb/ubuntu/simplesamlphp?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.1-1.1ubuntu0.1~esm1

Affected versions

1.*
1.19.1-1
1.19.1-1.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "simplesamlphp",
            "binary_version": "1.19.1-1.1ubuntu0.1~esm1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2024-52596",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-27773",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:22.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8770-1.json"

Ubuntu:24.04:LTS / simplesamlphp

Package

Name
simplesamlphp
Purl
pkg:deb/ubuntu/simplesamlphp?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.19.7-1+deb12u1ubuntu0.1

Affected versions

1.*
1.19.7-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "simplesamlphp",
            "binary_version": "1.19.7-1+deb12u1ubuntu0.1"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2024-52596",
            "severity": [
                {
                    "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:L/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2025-27773",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8770-1.json"