Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78fq-w796-q537

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

Пакеты

Наименование

org.opensaml:opensaml

maven
Затронутые версииВерсия исправления

<= 2.6.4

2.6.5

Наименование

edu.internet2.middleware:shibboleth-identityprovider

maven
Затронутые версииВерсия исправления

<= 2.4.3

2.4.4

EPSS

Процентиль: 38%
0.00166
Низкий

Дефекты

CWE-295

Связанные уязвимости

ubuntu
больше 10 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

redhat
почти 11 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

nvd
больше 10 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

debian
больше 10 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 an ...

EPSS

Процентиль: 38%
0.00166
Низкий

Дефекты

CWE-295