Vulnerabilities (CVE)

Filtered by vendor Shibboleth Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-6440 2 Internet2, Shibboleth 2 Opensaml, Opensaml 2022-02-07 5.0 MEDIUM N/A
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows remote attackers to conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE declaration.
CVE-2011-2516 2 Apache, Shibboleth 2 Xml Security For C\+\+, Shibboleth-sp 2021-09-17 5.0 MEDIUM N/A
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
CVE-2015-2684 2 Debian, Shibboleth 2 Debian Linux, Service Provider 2016-12-03 4.0 MEDIUM N/A
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
CVE-2015-1796 1 Shibboleth 2 Identity Provider, Opensaml Java 2016-11-30 4.3 MEDIUM N/A
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
CVE-2011-1411 1 Shibboleth 2 Opensaml, Shibboleth-identity-provider 2013-10-11 5.8 MEDIUM N/A
Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."