USN-8770-1: SimpleSAMLphp vulnerabilities
USN-8770-1
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.