Moderate severityNVD Advisory· Published Jul 8, 2015· Updated May 6, 2026
CVE-2015-1796
CVE-2015-1796
Description
The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.opensaml:opensamlMaven | < 2.6.5 | 2.6.5 |
edu.internet2.middleware:shibboleth-identityproviderMaven | < 2.4.4 | 2.4.4 |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/advisories/GHSA-78fq-w796-q537ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-1796ghsaADVISORY
- shibboleth.net/community/advisories/secadv_20150225.txtnvdVendor AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2015-1176.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2015-1177.htmlnvdWEB
- www.securityfocus.com/bid/75370nvd
News mentions
0No linked articles in our index yet.