Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1796

Опубликовано: 25 фев. 2015
Источник: redhat
CVSS2: 6.3

Описание

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

It was found that PKIX trust components allowed an X.509 credential to be trusted if no trusted names were available for the entityID. An attacker could use a certificate issued by a shibmd:KeyAuthority trust anchor to impersonate an entity within the scope of that keyAuthority.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6opensaml-javaAffected
Red Hat JBoss Data Virtualization 6opensamlAffected
Red Hat JBoss Enterprise Application Platform 5opensamlAffected
Red Hat JBoss Enterprise Application Platform 6opensamlAffected
Red Hat JBoss Fuse Service Works 6opensamlAffected
Red Hat JBoss Operations Network 3opensamlAffected
Red Hat JBoss Portal 5opensamlAffected
Red Hat JBoss Portal 6opensamlAffected
Red Hat JBoss A-MQ 6.2FixedRHSA-2015:117723.06.2015
Red Hat JBoss Fuse 6.2FixedRHSA-2015:117623.06.2015

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1196619Java: PKIX Trust Engines Exhibit Critical Flaw In Trusted Names Evaluation

6.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

nvd
около 11 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

debian
около 11 лет назад

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 an ...

github
около 4 лет назад

Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML

6.3 Medium

CVSS2