Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-6254

Опубликовано: 17 авг. 2015
Источник: nvd
CVSS2: 6
EPSS Низкий

Описание

The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:picketlink:picketlink:*:cr5:*:*:*:*:*:*
Версия до 2.6.0 (включая)

EPSS

Процентиль: 71%
0.00697
Низкий

6 Medium

CVSS2

Дефекты

CWE-17

Связанные уязвимости

CVSS3: 6.3
redhat
почти 11 лет назад

The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.

github
больше 3 лет назад

The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.

EPSS

Процентиль: 71%
0.00697
Низкий

6 Medium

CVSS2

Дефекты

CWE-17