Medium severity5.3NVD Advisory· Published Mar 22, 2021· Updated Jun 17, 2026
CVE-2021-28963
CVE-2021-28963
Description
Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:*range: <3.2.1
- (no CPE)range: <3.2.1
- Shibboleth/Shibboleth Service Providerdescription
- Range: <3.2.1
Patches
Vulnerability mechanics
References
5- issues.shibboleth.net/jira/browse/SSPCPP-922nvdIssue TrackingPatchVendor Advisory
- bugs.debian.org/985405nvdMailing ListThird Party Advisory
- shibboleth.net/community/advisories/secadv_20210317.txtnvdVendor Advisory
- www.debian.org/security/2021/dsa-4872nvdMailing ListThird Party Advisory
- git.shibboleth.net/view/nvd
News mentions
0No linked articles in our index yet.