Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-36661

Опубликовано: 25 июн. 2023
Источник: debian

Описание

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xmltoolingfixed3.2.4-1package

Примечания

  • https://shibboleth.net/community/advisories/secadv_20230612.txt

  • https://git.shibboleth.net/view/?p=cpp-xmltooling.git;a=commit;h=6080f6343f98fec085bc0fd746913ee418cc9d30

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

redhat
больше 2 лет назад

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

CVSS3: 7.5
nvd
больше 2 лет назад

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

suse-cvrf
больше 2 лет назад

Security update for xmltooling

suse-cvrf
больше 2 лет назад

Security update for xmltooling