Описание
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
It was found that PKIX trust components allowed an X.509 credential to be trusted if no trusted names were available for the entityID. An attacker could use a certificate issued by a shibmd:KeyAuthority trust anchor to impersonate an entity within the scope of that keyAuthority.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Data Grid 6 | opensaml-java | Affected | ||
| Red Hat JBoss Data Virtualization 6 | opensaml | Affected | ||
| Red Hat JBoss Enterprise Application Platform 5 | opensaml | Affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | opensaml | Affected | ||
| Red Hat JBoss Fuse Service Works 6 | opensaml | Affected | ||
| Red Hat JBoss Operations Network 3 | opensaml | Affected | ||
| Red Hat JBoss Portal 5 | opensaml | Affected | ||
| Red Hat JBoss Portal 6 | opensaml | Affected | ||
| Red Hat JBoss A-MQ 6.2 | Fixed | RHSA-2015:1177 | 23.06.2015 | |
| Red Hat JBoss Fuse 6.2 | Fixed | RHSA-2015:1176 | 23.06.2015 |
Показывать по
Дополнительная информация
Статус:
6.3 Medium
CVSS2
Связанные уязвимости
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 an ...
Improper Certificate Validation in Shibboleth Identity Provider and OpenSAML
6.3 Medium
CVSS2