Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2018-0486

Disclosure Date: January 13, 2018 (last updated November 26, 2024)
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.
0
Attacker Value
Unknown

CVE-2017-16853

Disclosure Date: November 16, 2017 (last updated November 08, 2023)
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.
0
Attacker Value
Unknown

CVE-2017-16852

Disclosure Date: November 16, 2017 (last updated November 08, 2023)
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
0
Attacker Value
Unknown

CVE-2017-14313

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of add_query_arg().
0
Attacker Value
Unknown

CVE-2015-1796

Disclosure Date: July 08, 2015 (last updated October 05, 2023)
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
0
Attacker Value
Unknown

CVE-2015-2684

Disclosure Date: March 31, 2015 (last updated October 05, 2023)
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
0
Attacker Value
Unknown

CVE-2013-6440

Disclosure Date: February 14, 2014 (last updated October 05, 2023)
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
0
Attacker Value
Unknown

CVE-2011-1411

Disclosure Date: September 02, 2011 (last updated October 04, 2023)
Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
0
Attacker Value
Unknown

CVE-2011-2516

Disclosure Date: July 11, 2011 (last updated October 04, 2023)
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
0