Описание
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
It was found that PKIX trust components allowed an X.509 credential to be trusted if no trusted names were available for the entityID. An attacker could use a certificate issued by a shibmd:KeyAuthority trust anchor to impersonate an entity within the scope of that keyAuthority.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Data Grid 6 | opensaml-java | Affected | ||
| Red Hat JBoss Data Virtualization 6 | opensaml | Affected | ||
| Red Hat JBoss Enterprise Application Platform 5 | opensaml | Affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | opensaml | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-6 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-esb-7 | Affected | ||
| Red Hat JBoss Fuse Service Works 6 | opensaml | Affected | ||
| Red Hat JBoss Operations Network 3 | opensaml | Affected | ||
| Red Hat JBoss Portal 5 | opensaml | Affected | ||
| Red Hat JBoss Portal 6 | opensaml | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.3 Medium
CVSS2
Связанные уязвимости
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 an ...
Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML
EPSS
6.3 Medium
CVSS2