SCA: security update for simplesamlphp/saml2 (GHSA-r8v4-7vwj-983x)

critical Tenable Self-Hosted Container Security Plugin ID 433518

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and
simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote
attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging
improper conversion of return values to boolean. (CVE-2016-9814)

See Also

https://github.com/advisories/GHSA-r8v4-7vwj-983x

Plugin Details

Severity: Critical

ID: 433518

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.06

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:C

CVSS Score Source: CVE-2016-9814

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/14/2022

Vulnerability Publication Date: 12/7/2016

Reference Information

CVE: CVE-2016-9814

BID: 94730