Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34v3-mf7p-7v76

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

EPSS

Процентиль: 72%
0.01531
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 8.7
redhat
больше 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
nvd
больше 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
debian
больше 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Pr ...

suse-cvrf
больше 8 лет назад

Security update for xmltooling

EPSS

Процентиль: 72%
0.01531
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-347