CVE-2012-2351: Debian Linux

Medium severity, CVSS 5.0. EPSS: 2.1% chance of exploitation in the next 30 days.

The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.

Affected products

  • Debian Debian Linux: version 6.0 only
  • Mahara Mahara: up to and including 1.4.1; version 0.9.0 only; version 0.9.1 only; version 0.9.2 only; version 1.0.0 only; version 1.0.1 only; …

Published 2012-07-12. Last modified 2026-06-16.