Skip to main content

Vendor archive

shibboleth CVEs

Beta · best-effort

18 CVEs tagged to vendor shibboleth0 Critical, 9 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2022-24129

Published Feb 4, 2022

The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insufficient restriction of the request_uri parameter. This allow…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31826

Published Apr 27, 2021

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on sy…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27978

Published Oct 28, 2020

Shibboleth Identify Provider 3.x before 3.4.6 has a denial of service flaw. A remote unauthenticated attacker can cause a login flow to trigger Java heap exhaustion due to the cre…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19191

Published Nov 21, 2019

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installatio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16853

Published Nov 16, 2017

The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the Metada…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6440

Published Feb 14, 2014

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1