Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-36661

Опубликовано: 26 июн. 2023
Источник: redhat

Описание

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7XMLToolingNot affected
Red Hat JBoss Data Virtualization 6XMLToolingOut of support scope
Red Hat JBoss Enterprise Application Platform 6XMLToolingOut of support scope
Red Hat JBoss Enterprise Application Platform 7xmltoolingNot affected
Red Hat JBoss Enterprise Application Platform 8xmltoolingNot affected
Red Hat JBoss Fuse 6xmltoolingOut of support scope
Red Hat Single Sign-On 7xmltoolingNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2217435XMLTooling: SSRF via a crafted KeyInfo element

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

CVSS3: 7.5
nvd
больше 2 лет назад

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This is fixed in, for example, Shibboleth Service Provider 3.4.1.3 on Windows.)

CVSS3: 7.5
debian
больше 2 лет назад

Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth ...

suse-cvrf
больше 2 лет назад

Security update for xmltooling

suse-cvrf
больше 2 лет назад

Security update for xmltooling