Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3474

Опубликовано: 29 сент. 2009
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:internet2:opensaml:2.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:opensaml:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:opensaml:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:xmltooling:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:internet2:xmltooling:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:xmltooling:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:internet2:xmltooling:1.2.0:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:internet2:shibboleth-sp:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:1.3b:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:1.3f:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:2.0:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:2.1:*:*:*:*:*:*:*
cpe:2.3:a:internet2:shibboleth-sp:2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01289
Низкий

7.5 High

CVSS2

Дефекты

CWE-310

Связанные уязвимости

ubuntu
около 16 лет назад

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

debian
около 16 лет назад

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by ...

github
больше 3 лет назад

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

EPSS

Процентиль: 79%
0.01289
Низкий

7.5 High

CVSS2

Дефекты

CWE-310