CVE-2017-12869: Debian Linux

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Simplesamlphp Simplesamlphp: up to and including 1.14.13

Published 2017-09-01. Last modified 2026-06-17.