SimpleSAMLphp Use of insecure connection charset (sqlauth module)
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 25, 2024
Description
Published by the National Vulnerability Database
Feb 2, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 25, 2024
Last updated
Apr 25, 2024
The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL utf8 charset, which truncates queries upon encountering four-byte characters. There might be a scenario in which this allows remote attackers to bypass intended access restrictions.
References