Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-31335

Опубликовано: 28 мар. 2025
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).

A flaw was found in the OpenSAML C++ library. This vulnerability allows forging signed SAML messages via parameter manipulation when using SAML bindings that rely on non-XML signatures.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopensaml-coreFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3quarkus-camel-bomNot affected
Red Hat build of Apache Camel 4 for Quarkus 3quarkus-cxf-bomNot affected
Red Hat build of Apache Camel for Spring Boot 4opensaml-coreNot affected
Red Hat Fuse 7opensaml-coreNot affected
Red Hat Integration Camel K 1opensaml-coreFix deferred
Red Hat JBoss Enterprise Application Platform 7opensaml-coreFix deferred
Red Hat JBoss Enterprise Application Platform 8opensaml-coreFix deferred
Red Hat JBoss Enterprise Application Platform 8org.jboss.eap-jboss-eap-xpNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packopensaml-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2355681opensaml-core: Signature Forgery in OpenSAML

EPSS

Процентиль: 15%
0.00238
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
больше 1 года назад

The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).

CVSS3: 4
nvd
больше 1 года назад

The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).

CVSS3: 4
debian
больше 1 года назад

The OpenSAML C++ library before 3.3.1 allows forging of signed SAML me ...

suse-cvrf
больше 1 года назад

Security update for opensaml

suse-cvrf
больше 1 года назад

Security update for opensaml

EPSS

Процентиль: 15%
0.00238
Низкий

4 Medium

CVSS3