Candidate: CVE-2012-2351 PublicDate: 2012-07-12 20:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2351 Description: The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_mahara: upstream_mahara: released (1.4.2-1) hardy_mahara: DNE lucid_mahara: ignored (reached end-of-life) natty_mahara: ignored (reached end-of-life) oneiric_mahara: ignored (reached end-of-life) precise_mahara: not-affected (1.4.2-1) quantal_mahara: not-affected raring_mahara: not-affected saucy_mahara: not-affected devel_mahara: DNE