Lucene search

K

Shibboleth Security Vulnerabilities

cve
cve

CVE-2023-22947

Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather...

7.3CVSS

7.1AI Score

0.0004EPSS

2023-01-11 02:15 AM
20
cve
cve

CVE-2021-31826

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is...

7.5CVSS

7.3AI Score

0.002EPSS

2021-04-27 04:15 AM
34
cve
cve

CVE-2017-16853

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity.....

8.1CVSS

7.8AI Score

0.01EPSS

2017-11-16 05:29 PM
36
cve
cve

CVE-2021-28963

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled...

5.3CVSS

5.3AI Score

0.002EPSS

2021-03-22 08:15 AM
35
cve
cve

CVE-2017-16852

shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity...

8.1CVSS

7.8AI Score

0.004EPSS

2017-11-16 05:29 PM
40
cve
cve

CVE-2023-36661

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on...

7.5CVSS

7.2AI Score

0.001EPSS

2023-06-25 10:15 PM
27
In Wild
cve
cve

CVE-2011-2516

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer...

6.7AI Score

0.026EPSS

2011-07-11 08:55 PM
37
cve
cve

CVE-2022-24129

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP...

8.2CVSS

8.2AI Score

0.006EPSS

2022-02-04 08:15 PM
36
cve
cve

CVE-2020-27978

Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the creation of objects in the Java Servlet container...

7.5CVSS

7.5AI Score

0.002EPSS

2020-10-28 03:15 PM
22
cve
cve

CVE-2019-19191

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as...

7.8CVSS

7.5AI Score

0.001EPSS

2019-11-21 06:15 PM
114
cve
cve

CVE-2010-2450

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable.....

7.5CVSS

7.4AI Score

0.007EPSS

2019-11-07 09:15 PM
23
cve
cve

CVE-2014-3603

The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which...

5.9CVSS

5.7AI Score

0.001EPSS

2019-04-04 02:29 PM
63
cve
cve

CVE-2018-0489

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this...

6.5CVSS

6.5AI Score

0.005EPSS

2018-02-27 03:29 PM
46
cve
cve

CVE-2018-0486

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted...

6.5CVSS

6AI Score

0.004EPSS

2018-01-13 06:29 PM
47
cve
cve

CVE-2017-14313

The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of...

6.1CVSS

5.8AI Score

0.001EPSS

2017-09-12 12:29 AM
40
cve
cve

CVE-2015-1796

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a...

8.2AI Score

0.004EPSS

2015-07-08 03:59 PM
83
2
cve
cve

CVE-2015-2684

Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML...

6AI Score

0.004EPSS

2015-03-31 02:59 PM
38
cve
cve

CVE-2013-6440

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE...

5.4AI Score

0.003EPSS

2014-02-14 03:55 PM
62
cve
cve

CVE-2011-1411

Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping...

6.7AI Score

0.006EPSS

2011-09-02 11:55 PM
51