The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html | mailing list |
https://www.debian.org/security/2018/dsa-4127 | vendor advisory |
https://simplesamlphp.org/security/201708-01 | patch vendor advisory |