Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pw72-xm42-hr32

Опубликовано: 10 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

EPSS

Процентиль: 94%
0.14561
Средний

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.2
nvd
около 4 лет назад

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allows attackers to interact with arbitrary third-party HTTP services.

EPSS

Процентиль: 94%
0.14561
Средний

Дефекты

CWE-918